slackware records
59 published records for vendor slackware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 40.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation2
- CWE-189 Numeric Errors1
- CWE-252 Unchecked Return Value1
- CWE-131 Incorrect Calculation of Buffer Size1
The weakness classes this vendor ships most often: where to look.
CWEAll records
59 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2007-3798Proof of concept | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craftcpdump · tcpdump · CWE-252 | Critical9.8 | — | 70.4% | Jul 16, 2007 |
52Plan | CVE-1999-0368Proof of concept | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.proftpd project · proftpd | Critical10.0 | — | 39.8% | Feb 9, 1999 |
45Plan | CVE-2000-0844Proof of concept | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackecaldera · openlinux ebuilder · CWE-264 | Critical10.0 | — | 15.6% | Nov 14, 2000 |
43Plan | CVE-1999-0192Proof of concept | Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.redhat · linux | Critical10.0 | — | 10.0% | Oct 18, 1997 |
42Plan | CVE-2004-0891No exploit | Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) rob flynn · gaim | Critical10.0 | — | 6.9% | Jan 27, 2005 |
42Plan | CVE-2006-6235No exploit | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Critical10.0 | — | 5.9% | Dec 7, 2006 |
41Plan | CVE-2013-4854No exploit | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco Bisc · bind | High7.8 | — | 34.2% | Jul 29, 2013 |
41Plan | CVE-2016-4448No exploit | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Critical9.8 | — | 7.0% | Jun 9, 2016 |
41Plan | CVE-2013-7171No exploit | Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could slackware · slackware linux · CWE-20 | Critical9.8 | — | 6.3% | Nov 21, 2019 |
41Plan | CVE-2007-6200No exploit | Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, excludrsync · rsync · CWE-264 | Critical10.0 | — | 4.9% | Dec 1, 2007 |
41Plan | CVE-2004-0226No exploit | Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary codemidnight commander · midnight commander | Critical10.0 | — | 3.9% | Aug 18, 2004 |
41Plan | CVE-2005-3625No exploit | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Critical10.0 | — | 3.8% | Dec 31, 2005 |
41Plan | CVE-1999-1299No exploit | rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, sincredhat · linux | Critical10.0 | — | 1.8% | Feb 3, 1997 |
38Monitor | CVE-2007-6199No exploit | rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files virsync · rsync · CWE-16 | Critical9.3 | — | 4.1% | Dec 1, 2007 |
36Monitor | CVE-2003-0962No exploit | Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possiblandrew tridgell · rsync | High7.5 | — | 21.2% | Dec 15, 2003 |
33Monitor | CVE-1999-0041Proof of concept | Buffer overflow in NLS (Natural Language Service).gnu · libc | High7.5 | — | 9.1% | Feb 13, 1997 |
33Monitor | CVE-2018-7184No exploit | ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denntp · ntp | High7.5 | — | 8.5% | Mar 6, 2018 |
32Monitor | CVE-2004-0940Proof of concept | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to executeapache · http server · CWE-131 | High7.8 | — | 4.8% | Feb 9, 2005 |
31Monitor | CVE-1999-0242No exploit | Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.slackware · slackware linux | High7.5 | — | 2.3% | Mar 1, 1995 |
31Monitor | CVE-2003-0977No exploit | CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via cvs · cvs | High7.5 | — | 2.3% | Jan 5, 2004 |
31Monitor | CVE-1999-0298No exploit | ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a ..slackware · slackware linux | High7.5 | — | 2.0% | Feb 5, 1997 |
31Monitor | CVE-2018-9336No exploit | openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory openvpn · openvpn · CWE-415 | High7.8 | — | 0.6% | May 1, 2018 |
31Monitor | CVE-2013-7172No exploit | Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc packageslackware · slackware linux · CWE-20 | High7.8 | — | 0.5% | Nov 21, 2019 |
30Monitor | CVE-2003-0335No exploit | rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant slackware · slackware linux | High7.5 | — | 1.1% | May 22, 2003 |
28Monitor | CVE-1999-0421No exploit | During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account witslackware · slackware linux | High7.2 | — | 1.6% | Mar 17, 1999 |
- CVE-2007-379860This week
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf
CriticalCVSS 9.8Proof of conceptEPSS 70%tcpdump · tcpdumpJul 16, 2007
- CVE-1999-036852Plan
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.
CriticalCVSS 10.0Proof of conceptEPSS 40%proftpd project · proftpdFeb 9, 1999
- CVE-2000-084445Plan
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attacke
CriticalCVSS 10.0Proof of conceptEPSS 16%caldera · openlinux ebuilderNov 14, 2000
- CVE-1999-019243Plan
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
CriticalCVSS 10.0Proof of conceptEPSS 10%redhat · linuxOct 18, 1997
- CVE-2004-089142Plan
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash)
CriticalCVSS 10.0No exploitEPSS 7%rob flynn · gaimJan 27, 2005
- CVE-2006-623542Plan
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
CriticalCVSS 10.0No exploitEPSS 6%gnu · privacy guardDec 7, 2006
- CVE-2013-485441Plan
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco B
HighCVSS 7.8No exploitEPSS 34%isc · bindJul 29, 2013
- CVE-2016-444841Plan
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
CriticalCVSS 9.8No exploitEPSS 7%hp · icewall federation agentJun 9, 2016
- CVE-2013-717141Plan
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could
CriticalCVSS 9.8No exploitEPSS 6%slackware · slackware linuxNov 21, 2019
- CVE-2007-620041Plan
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclud
CriticalCVSS 10.0No exploitEPSS 5%rsync · rsyncDec 1, 2007
- CVE-2004-022641Plan
Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code
CriticalCVSS 10.0No exploitEPSS 4%midnight commander · midnight commanderAug 18, 2004
- CVE-2005-362541Plan
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
CriticalCVSS 10.0No exploitEPSS 4%libextractor · libextractorDec 31, 2005
- CVE-1999-129941Plan
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, sinc
CriticalCVSS 10.0No exploitEPSS 2%redhat · linuxFeb 3, 1997
- CVE-2007-619938Monitor
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files vi
CriticalCVSS 9.3No exploitEPSS 4%rsync · rsyncDec 1, 2007
- CVE-2003-096236Monitor
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibl
HighCVSS 7.5No exploitEPSS 21%andrew tridgell · rsyncDec 15, 2003
- CVE-1999-004133Monitor
Buffer overflow in NLS (Natural Language Service).
HighCVSS 7.5Proof of conceptEPSS 9%gnu · libcFeb 13, 1997
- CVE-2018-718433Monitor
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a den
HighCVSS 7.5No exploitEPSS 9%ntp · ntpMar 6, 2018
- CVE-2004-094032Monitor
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute
HighCVSS 7.8Proof of conceptEPSS 5%apache · http serverFeb 9, 2005
- CVE-1999-024231Monitor
Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.
HighCVSS 7.5No exploitEPSS 2%slackware · slackware linuxMar 1, 1995
- CVE-2003-097731Monitor
CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via
HighCVSS 7.5No exploitEPSS 2%cvs · cvsJan 5, 2004
- CVE-1999-029831Monitor
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a ..
HighCVSS 7.5No exploitEPSS 2%slackware · slackware linuxFeb 5, 1997
- CVE-2018-933631Monitor
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory
HighCVSS 7.8No exploitEPSS 1%openvpn · openvpnMay 1, 2018
- CVE-2013-717231Monitor
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package
HighCVSS 7.8No exploitEPSS 0%slackware · slackware linuxNov 21, 2019
- CVE-2003-033530Monitor
rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant
HighCVSS 7.5No exploitEPSS 1%slackware · slackware linuxMay 22, 2003
- CVE-1999-042128Monitor
During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account wit
HighCVSS 7.2No exploitEPSS 2%slackware · slackware linuxMar 17, 1999