suckless records
3 published records for vendor suckless.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2016-6866No exploit | slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference asuckless · slock · CWE-476 | High7.5 | — | 2.9% | Feb 15, 2017 |
22Monitor | CVE-2012-0842No exploit | surf: cookie jar has read access from other local usersuckless · surf · CWE-200 | Medium5.5 | — | 0.4% | Nov 19, 2019 |
14Monitor | CVE-2012-1620No exploit | slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtsuckless · slock · CWE-264 | Low3.6 | — | 0.5% | Jul 12, 2012 |
- CVE-2016-686631Monitor
slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference a
HighCVSS 7.5No exploitEPSS 3%suckless · slockFeb 15, 2017
- CVE-2012-084222Monitor
surf: cookie jar has read access from other local user
MediumCVSS 5.5No exploitEPSS 0%suckless · surfNov 19, 2019
- CVE-2012-162014Monitor
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obt
LowCVSS 3.6No exploitEPSS 1%suckless · slockJul 12, 2012