ISOMAN

Filtered CVEs

slackware64-14.0-install-dvd.iso CVEs

CVEs linked through Slackware 14.0 x86_64 install-dvd.

Release Context

  1. Slackware · 14.0 x86_64 install-dvd

11 CVEs

  1. CVE-2013-7172
    HIGH · CVSS 7.8 ·

    Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.

  2. CVE-2013-7171
    CRITICAL · CVSS 9.8 ·

    Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.

  3. CVE-2018-9336
    HIGH · CVSS 7.8 ·

    openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

  4. CVE-2018-7184
    HIGH · CVSS 7.5 ·

    ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.

  5. CVE-2016-4448
    CRITICAL · CVSS 9.8 ·

    Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

  6. CVE-2004-0226
    HIGH · CVSS 10 ·

    Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  7. CVE-2004-0231
    LOW · CVSS 2.1 ·

    Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

  8. CVE-2004-0232
    MEDIUM · CVSS 5 ·

    Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  9. CVE-2004-0233
    LOW · CVSS 2.1 ·

    Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

  10. CVE-2000-0867
    HIGH · CVSS 7.2 ·

    Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.

  11. CVE-1999-0242
    HIGH · CVSS 7.5 ·

    Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.