Pacman is a lightweight package manager widely deployed across Linux distributions, particularly Arch Linux and its derivatives, where its command-execution and file-access patterns create a naturally exposed surface. The vulnerability profile clusters around its core pacman product and reflects recurring weaknesses in OS command injection, path traversal, and out-of-bounds read conditions that arise in package-handling and script-execution contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pacman Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18183CRITICAL pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To expl | Feb 24, 2020 | 9.8 | 32 | NO | NO |
CVE-2019-18182CRITICAL pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exp | Feb 24, 2020 | 9.8 | 32 | NO | NO |
CVE-2019-9686HIGH pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Dispos | Mar 11, 2019 | 8.8 | 24 | NO | NO |
CVE-2016-5434MEDIUM libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature file. | Jan 30, 2017 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pacman Project.
Media articles that mention a CVE ID that affects a product developed by Pacman Project — matched by CVE ID, not by vendor name.