Conky is a lightweight system monitoring and desktop widget application, narrowly focused with a minimal disclosure footprint. Its durable signal centers on improper link resolution preceding file access, a weakness class characteristic of tools that read configuration or data files from user-writable directories. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Conky over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3616MEDIUM The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf. | Nov 4, 2011 | 6.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Conky.
Media articles that mention a CVE ID that affects a product developed by Conky — matched by CVE ID, not by vendor name.