Записи slackware
59 опубликованных записей вендора slackware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 40,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation2
- CWE-189 Numeric Errors1
- CWE-252 Unchecked Return Value1
- CWE-131 Incorrect Calculation of Buffer Size1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
59 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2007-3798Proof of concept | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craftcpdump · tcpdump · CWE-252 | Критическая9,8 | — | 70,4 % | 16 июл. 2007 г. |
52В плане | CVE-1999-0368Proof of concept | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.proftpd project · proftpd | Критическая10,0 | — | 39,8 % | 9 февр. 1999 г. |
45В плане | CVE-2000-0844Proof of concept | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackecaldera · openlinux ebuilder · CWE-264 | Критическая10,0 | — | 15,6 % | 14 нояб. 2000 г. |
43В плане | CVE-1999-0192Proof of concept | Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.redhat · linux | Критическая10,0 | — | 10,0 % | 18 окт. 1997 г. |
42В плане | CVE-2004-0891Эксплойта нет | Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) rob flynn · gaim | Критическая10,0 | — | 6,9 % | 27 янв. 2005 г. |
42В плане | CVE-2006-6235Эксплойта нет | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Критическая10,0 | — | 5,9 % | 7 дек. 2006 г. |
41В плане | CVE-2013-4854Эксплойта нет | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco Bisc · bind | Высокая7,8 | — | 34,2 % | 29 июл. 2013 г. |
41В плане | CVE-2016-4448Эксплойта нет | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Критическая9,8 | — | 7,0 % | 9 июн. 2016 г. |
41В плане | CVE-2013-7171Эксплойта нет | Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could slackware · slackware linux · CWE-20 | Критическая9,8 | — | 6,3 % | 21 нояб. 2019 г. |
41В плане | CVE-2007-6200Эксплойта нет | Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, excludrsync · rsync · CWE-264 | Критическая10,0 | — | 4,9 % | 1 дек. 2007 г. |
41В плане | CVE-2004-0226Эксплойта нет | Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary codemidnight commander · midnight commander | Критическая10,0 | — | 3,9 % | 18 авг. 2004 г. |
41В плане | CVE-2005-3625Эксплойта нет | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Критическая10,0 | — | 3,8 % | 31 дек. 2005 г. |
41В плане | CVE-1999-1299Эксплойта нет | rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, sincredhat · linux | Критическая10,0 | — | 1,8 % | 3 февр. 1997 г. |
38Наблюдать | CVE-2007-6199Эксплойта нет | rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files virsync · rsync · CWE-16 | Критическая9,3 | — | 4,1 % | 1 дек. 2007 г. |
36Наблюдать | CVE-2003-0962Эксплойта нет | Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possiblandrew tridgell · rsync | Высокая7,5 | — | 21,2 % | 15 дек. 2003 г. |
33Наблюдать | CVE-1999-0041Proof of concept | Buffer overflow in NLS (Natural Language Service).gnu · libc | Высокая7,5 | — | 9,1 % | 13 февр. 1997 г. |
33Наблюдать | CVE-2018-7184Эксплойта нет | ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denntp · ntp | Высокая7,5 | — | 8,5 % | 6 мар. 2018 г. |
32Наблюдать | CVE-2004-0940Proof of concept | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to executeapache · http server · CWE-131 | Высокая7,8 | — | 4,8 % | 9 февр. 2005 г. |
31Наблюдать | CVE-1999-0242Эксплойта нет | Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.slackware · slackware linux | Высокая7,5 | — | 2,3 % | 1 мар. 1995 г. |
31Наблюдать | CVE-2003-0977Эксплойта нет | CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via cvs · cvs | Высокая7,5 | — | 2,3 % | 5 янв. 2004 г. |
31Наблюдать | CVE-1999-0298Эксплойта нет | ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a ..slackware · slackware linux | Высокая7,5 | — | 2,0 % | 5 февр. 1997 г. |
31Наблюдать | CVE-2018-9336Эксплойта нет | openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory openvpn · openvpn · CWE-415 | Высокая7,8 | — | 0,6 % | 1 мая 2018 г. |
31Наблюдать | CVE-2013-7172Эксплойта нет | Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc packageslackware · slackware linux · CWE-20 | Высокая7,8 | — | 0,5 % | 21 нояб. 2019 г. |
30Наблюдать | CVE-2003-0335Эксплойта нет | rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant slackware · slackware linux | Высокая7,5 | — | 1,1 % | 22 мая 2003 г. |
28Наблюдать | CVE-1999-0421Эксплойта нет | During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account witslackware · slackware linux | Высокая7,2 | — | 1,6 % | 17 мар. 1999 г. |
- CVE-2007-379860На этой неделе
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf
КритическаяCVSS 9,8Proof of conceptEPSS 70 %tcpdump · tcpdump16 июл. 2007 г.
- CVE-1999-036852В плане
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.
КритическаяCVSS 10,0Proof of conceptEPSS 40 %proftpd project · proftpd9 февр. 1999 г.
- CVE-2000-084445В плане
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attacke
КритическаяCVSS 10,0Proof of conceptEPSS 16 %caldera · openlinux ebuilder14 нояб. 2000 г.
- CVE-1999-019243В плане
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
КритическаяCVSS 10,0Proof of conceptEPSS 10 %redhat · linux18 окт. 1997 г.
- CVE-2004-089142В плане
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash)
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %rob flynn · gaim27 янв. 2005 г.
- CVE-2006-623542В плане
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %gnu · privacy guard7 дек. 2006 г.
- CVE-2013-485441В плане
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco B
ВысокаяCVSS 7,8Эксплойта нетEPSS 34 %isc · bind29 июл. 2013 г.
- CVE-2016-444841В плане
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · icewall federation agent9 июн. 2016 г.
- CVE-2013-717141В плане
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %slackware · slackware linux21 нояб. 2019 г.
- CVE-2007-620041В плане
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclud
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %rsync · rsync1 дек. 2007 г.
- CVE-2004-022641В плане
Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %midnight commander · midnight commander18 авг. 2004 г.
- CVE-2005-362541В плане
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %libextractor · libextractor31 дек. 2005 г.
- CVE-1999-129941В плане
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, sinc
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %redhat · linux3 февр. 1997 г.
- CVE-2007-619938Наблюдать
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files vi
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %rsync · rsync1 дек. 2007 г.
- CVE-2003-096236Наблюдать
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibl
ВысокаяCVSS 7,5Эксплойта нетEPSS 21 %andrew tridgell · rsync15 дек. 2003 г.
- CVE-1999-004133Наблюдать
Buffer overflow in NLS (Natural Language Service).
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %gnu · libc13 февр. 1997 г.
- CVE-2018-718433Наблюдать
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a den
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %ntp · ntp6 мар. 2018 г.
- CVE-2004-094032Наблюдать
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute
ВысокаяCVSS 7,8Proof of conceptEPSS 5 %apache · http server9 февр. 2005 г.
- CVE-1999-024231Наблюдать
Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %slackware · slackware linux1 мар. 1995 г.
- CVE-2003-097731Наблюдать
CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cvs · cvs5 янв. 2004 г.
- CVE-1999-029831Наблюдать
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a ..
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %slackware · slackware linux5 февр. 1997 г.
- CVE-2018-933631Наблюдать
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %openvpn · openvpn1 мая 2018 г.
- CVE-2013-717231Наблюдать
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %slackware · slackware linux21 нояб. 2019 г.
- CVE-2003-033530Наблюдать
rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %slackware · slackware linux22 мая 2003 г.
- CVE-1999-042128Наблюдать
During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account wit
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %slackware · slackware linux17 мар. 1999 г.