ISOMAN

Filtered CVEs

slackware64-13.37-install-dvd.iso CVEs

CVEs linked through Slackware 13.37 x86_64 install-dvd.

Release Context

  1. Slackware · 13.37 x86_64 install-dvd

9 CVEs

  1. CVE-2013-7172
    HIGH · CVSS 7.8 ·

    Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.

  2. CVE-2018-9336
    HIGH · CVSS 7.8 ·

    openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

  3. CVE-2013-4854
    HIGH · CVSS 7.8 ·

    The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.

  4. CVE-2004-0226
    HIGH · CVSS 10 ·

    Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  5. CVE-2004-0231
    LOW · CVSS 2.1 ·

    Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

  6. CVE-2004-0232
    MEDIUM · CVSS 5 ·

    Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  7. CVE-2004-0233
    LOW · CVSS 2.1 ·

    Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

  8. CVE-2000-0867
    HIGH · CVSS 7.2 ·

    Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.

  9. CVE-1999-0242
    HIGH · CVSS 7.5 ·

    Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.