slackware kayıtları
slackware üreticisine ait 59 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %40,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-399 Resource Management Errors2
- CWE-20 Improper Input Validation2
- CWE-189 Numeric Errors1
- CWE-252 Unchecked Return Value1
- CWE-131 Incorrect Calculation of Buffer Size1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
59 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2007-3798Kavram kanıtı | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craftcpdump · tcpdump · CWE-252 | Kritik9,8 | — | %70,4 | 16 Tem 2007 |
52Planlayın | CVE-1999-0368Kavram kanıtı | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.proftpd project · proftpd | Kritik10,0 | — | %39,8 | 9 Şub 1999 |
45Planlayın | CVE-2000-0844Kavram kanıtı | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackecaldera · openlinux ebuilder · CWE-264 | Kritik10,0 | — | %15,6 | 14 Kas 2000 |
43Planlayın | CVE-1999-0192Kavram kanıtı | Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.redhat · linux | Kritik10,0 | — | %10,0 | 18 Eki 1997 |
42Planlayın | CVE-2004-0891İstismar yok | Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) rob flynn · gaim | Kritik10,0 | — | %6,9 | 27 Oca 2005 |
42Planlayın | CVE-2006-6235İstismar yok | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Kritik10,0 | — | %5,9 | 7 Ara 2006 |
41Planlayın | CVE-2013-4854İstismar yok | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco Bisc · bind | Yüksek7,8 | — | %34,2 | 29 Tem 2013 |
41Planlayın | CVE-2016-4448İstismar yok | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Kritik9,8 | — | %7,0 | 9 Haz 2016 |
41Planlayın | CVE-2013-7171İstismar yok | Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could slackware · slackware linux · CWE-20 | Kritik9,8 | — | %6,3 | 21 Kas 2019 |
41Planlayın | CVE-2007-6200İstismar yok | Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, excludrsync · rsync · CWE-264 | Kritik10,0 | — | %4,9 | 1 Ara 2007 |
41Planlayın | CVE-2004-0226İstismar yok | Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary codemidnight commander · midnight commander | Kritik10,0 | — | %3,9 | 18 Ağu 2004 |
41Planlayın | CVE-2005-3625İstismar yok | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Kritik10,0 | — | %3,8 | 31 Ara 2005 |
41Planlayın | CVE-1999-1299İstismar yok | rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, sincredhat · linux | Kritik10,0 | — | %1,8 | 3 Şub 1997 |
38İzleyin | CVE-2007-6199İstismar yok | rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files virsync · rsync · CWE-16 | Kritik9,3 | — | %4,1 | 1 Ara 2007 |
36İzleyin | CVE-2003-0962İstismar yok | Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possiblandrew tridgell · rsync | Yüksek7,5 | — | %21,2 | 15 Ara 2003 |
33İzleyin | CVE-1999-0041Kavram kanıtı | Buffer overflow in NLS (Natural Language Service).gnu · libc | Yüksek7,5 | — | %9,1 | 13 Şub 1997 |
33İzleyin | CVE-2018-7184İstismar yok | ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denntp · ntp | Yüksek7,5 | — | %8,5 | 6 Mar 2018 |
32İzleyin | CVE-2004-0940Kavram kanıtı | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to executeapache · http server · CWE-131 | Yüksek7,8 | — | %4,8 | 9 Şub 2005 |
31İzleyin | CVE-1999-0242İstismar yok | Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.slackware · slackware linux | Yüksek7,5 | — | %2,3 | 1 Mar 1995 |
31İzleyin | CVE-2003-0977İstismar yok | CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via cvs · cvs | Yüksek7,5 | — | %2,3 | 5 Oca 2004 |
31İzleyin | CVE-1999-0298İstismar yok | ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a ..slackware · slackware linux | Yüksek7,5 | — | %2,0 | 5 Şub 1997 |
31İzleyin | CVE-2018-9336İstismar yok | openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory openvpn · openvpn · CWE-415 | Yüksek7,8 | — | %0,6 | 1 May 2018 |
31İzleyin | CVE-2013-7172İstismar yok | Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc packageslackware · slackware linux · CWE-20 | Yüksek7,8 | — | %0,5 | 21 Kas 2019 |
30İzleyin | CVE-2003-0335İstismar yok | rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant slackware · slackware linux | Yüksek7,5 | — | %1,1 | 22 May 2003 |
28İzleyin | CVE-1999-0421İstismar yok | During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account witslackware · slackware linux | Yüksek7,2 | — | %1,6 | 17 Mar 1999 |
- CVE-2007-379860Bu hafta
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf
KritikCVSS 9,8Kavram kanıtıEPSS %70tcpdump · tcpdump16 Tem 2007
- CVE-1999-036852Planlayın
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.
KritikCVSS 10,0Kavram kanıtıEPSS %40proftpd project · proftpd9 Şub 1999
- CVE-2000-084445Planlayın
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attacke
KritikCVSS 10,0Kavram kanıtıEPSS %16caldera · openlinux ebuilder14 Kas 2000
- CVE-1999-019243Planlayın
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
KritikCVSS 10,0Kavram kanıtıEPSS %10redhat · linux18 Eki 1997
- CVE-2004-089142Planlayın
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash)
KritikCVSS 10,0İstismar yokEPSS %7rob flynn · gaim27 Oca 2005
- CVE-2006-623542Planlayın
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
KritikCVSS 10,0İstismar yokEPSS %6gnu · privacy guard7 Ara 2006
- CVE-2013-485441Planlayın
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco B
YüksekCVSS 7,8İstismar yokEPSS %34isc · bind29 Tem 2013
- CVE-2016-444841Planlayın
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
KritikCVSS 9,8İstismar yokEPSS %7hp · icewall federation agent9 Haz 2016
- CVE-2013-717141Planlayın
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could
KritikCVSS 9,8İstismar yokEPSS %6slackware · slackware linux21 Kas 2019
- CVE-2007-620041Planlayın
Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclud
KritikCVSS 10,0İstismar yokEPSS %5rsync · rsync1 Ara 2007
- CVE-2004-022641Planlayın
Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code
KritikCVSS 10,0İstismar yokEPSS %4midnight commander · midnight commander18 Ağu 2004
- CVE-2005-362541Planlayın
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
KritikCVSS 10,0İstismar yokEPSS %4libextractor · libextractor31 Ara 2005
- CVE-1999-129941Planlayın
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, sinc
KritikCVSS 10,0İstismar yokEPSS %2redhat · linux3 Şub 1997
- CVE-2007-619938İzleyin
rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files vi
KritikCVSS 9,3İstismar yokEPSS %4rsync · rsync1 Ara 2007
- CVE-2003-096236İzleyin
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibl
YüksekCVSS 7,5İstismar yokEPSS %21andrew tridgell · rsync15 Ara 2003
- CVE-1999-004133İzleyin
Buffer overflow in NLS (Natural Language Service).
YüksekCVSS 7,5Kavram kanıtıEPSS %9gnu · libc13 Şub 1997
- CVE-2018-718433İzleyin
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a den
YüksekCVSS 7,5İstismar yokEPSS %9ntp · ntp6 Mar 2018
- CVE-2004-094032İzleyin
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute
YüksekCVSS 7,8Kavram kanıtıEPSS %5apache · http server9 Şub 2005
- CVE-1999-024231İzleyin
Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.
YüksekCVSS 7,5İstismar yokEPSS %2slackware · slackware linux1 Mar 1995
- CVE-2003-097731İzleyin
CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via
YüksekCVSS 7,5İstismar yokEPSS %2cvs · cvs5 Oca 2004
- CVE-1999-029831İzleyin
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a ..
YüksekCVSS 7,5İstismar yokEPSS %2slackware · slackware linux5 Şub 1997
- CVE-2018-933631İzleyin
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory
YüksekCVSS 7,8İstismar yokEPSS %1openvpn · openvpn1 May 2018
- CVE-2013-717231İzleyin
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package
YüksekCVSS 7,8İstismar yokEPSS %0slackware · slackware linux21 Kas 2019
- CVE-2003-033530İzleyin
rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant
YüksekCVSS 7,5İstismar yokEPSS %1slackware · slackware linux22 May 2003
- CVE-1999-042128İzleyin
During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account wit
YüksekCVSS 7,2İstismar yokEPSS %2slackware · slackware linux17 Mar 1999