ISOMAN

Filtered CVEs

Slackware CVEs

CVEs linked to tracked Slackware releases.

Release Context

  1. Slackware · 12.0 x86 install-d1
  2. Slackware · 12.0 x86 install-d2
  3. Slackware · 12.0 x86 install-d3
  4. Slackware · 12.0 x86 install-dvd
  5. Slackware · 12.0 x86 source-d4
  6. Slackware · 12.0 x86 source-d5
  7. Slackware · 12.0 x86 source-d6
  8. Slackware · 12.1 x86 install-d1
  9. Slackware · 12.1 x86 install-d2
  10. Slackware · 12.1 x86 install-d3
  11. Slackware · 12.1 x86 install-dvd
  12. Slackware · 12.1 x86 source-d4
  13. Slackware · 12.1 x86 source-d5
  14. Slackware · 12.1 x86 source-d6
  15. Slackware · 12.2 x86 install-d1
  16. Slackware · 12.2 x86 install-d2
  17. Slackware · 12.2 x86 install-d3
  18. Slackware · 12.2 x86 install-dvd
  19. Slackware · 12.2 x86 source-d4
  20. Slackware · 12.2 x86 source-d5
  21. Slackware · 12.2 x86 source-d6
  22. Slackware · 13.0 x86 install-d1
  23. Slackware · 13.0 x86 install-d2
  24. Slackware · 13.0 x86 install-d3
  25. Slackware · 13.0 x86 install-dvd
  26. Slackware · 13.0 x86 source-d4
  27. Slackware · 13.0 x86 source-d5
  28. Slackware · 13.0 x86 source-d6
  29. Slackware · 13.1 x86 install-d1
  30. Slackware · 13.1 x86 install-d2
  31. Slackware · 13.1 x86 install-d3
  32. Slackware · 13.1 x86 install-dvd
  33. Slackware · 13.1 x86 source-d4
  34. Slackware · 13.1 x86 source-d5
  35. Slackware · 13.1 x86 source-d6
  36. Slackware · 13.37 x86 install-d1
  37. Slackware · 13.37 x86 install-d2
  38. Slackware · 13.37 x86 install-d3
  39. Slackware · 13.37 x86 install-d4
  40. Slackware · 13.37 x86 install-dvd

14 CVEs

  1. CVE-2013-7172
    HIGH · CVSS 7.8 ·

    Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.

  2. CVE-2013-7171
    CRITICAL · CVSS 9.8 ·

    Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.

  3. CVE-2018-9336
    HIGH · CVSS 7.8 ·

    openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

  4. CVE-2018-7184
    HIGH · CVSS 7.5 ·

    ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.

  5. CVE-2016-4448
    CRITICAL · CVSS 9.8 ·

    Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

  6. CVE-2013-4854
    HIGH · CVSS 7.8 ·

    The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.

  7. CVE-2007-6199
    HIGH · CVSS 9.3 ·

    rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to create a symlink that points outside of the module's hierarchy.

  8. CVE-2007-6200
    HIGH · CVSS 10 ·

    Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.

  9. CVE-2004-0226
    HIGH · CVSS 10 ·

    Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  10. CVE-2004-0231
    LOW · CVSS 2.1 ·

    Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

  11. CVE-2004-0232
    MEDIUM · CVSS 5 ·

    Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  12. CVE-2004-0233
    LOW · CVSS 2.1 ·

    Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

  13. CVE-2000-0867
    HIGH · CVSS 7.2 ·

    Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.

  14. CVE-1999-0242
    HIGH · CVSS 7.5 ·

    Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.