📦

slackware_linux

Vendor: slackware

Actively Exploited 0 CISA KEV List
PoC / Exploits 7 Code Available
Total RCEs 3 Remote Access
Total CVEs 67 Total Indexed
Avg. EPSS 2.10% Exploit Prob.
Latest CVE CVE-2013-7172 Nov 21

Security Vulnerability Index

Page 1 / 7
7.8 CVSS

Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.

EPSS: 0.46%
9.8 CVSS

Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.

EPSS: 6.34%
1.9 CVSS

xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory. NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.

EPSS: 0.44%
7.2 CVSS

The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.

EPSS: 0.41%
5.0 CVSS
CVE-2003-0195
Exploit Found

CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.

EPSS: 10.61%
7.5 CVSS

rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec.

EPSS: 1.14%
5.0 CVSS

traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.

EPSS: 1.75%
5.0 CVSS

traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.

EPSS: 1.75%
7.2 CVSS

Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.

EPSS: 0.41%
7.2 CVSS
CVE-2000-0438
Exploit Found

Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.

EPSS: 1.08%