Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Slackware

First CVE: Mar 1, 1995Active for: 31 yearsTotal CVEs: 59
59.5
VTI Score
TOP TARGET

Slackware is a distribution of Linux that, despite a narrow product scope, holds a position among the more prominent distributions in the landscape and carries a noteworthy vulnerability footprint. The vendor's vulnerabilities span a moderate share of serious-severity outcomes and frequently acquire public exploit code, reflecting both the maturity and widespread deployment of the operating system across server and workstation environments. The recurring weakness classes—including improper input validation, double-free conditions, and incorrect buffer-size calculations—are endemic to the native codebases bundled in the distribution and recur across its core packages rather than concentrated in a single application. Defenders tracking this distribution should prioritize its advisory streams and patch cycles, as individual flaws can propagate across many downstream systems; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
59
Total CVEs
More Total CVEs than 99% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Slackware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 1995
31 years ago
Most Recent CVE
Nov 21, 2019
2,437 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (59 CVEs).

59 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-3798CRITICAL
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an
Jul 16, 20079.878NOYES
CVE-1999-0368HIGH
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Feb 9, 199910.060NOYES
CVE-2000-0844HIGH
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun
Nov 14, 200010.044NOYES
CVE-1999-0192HIGH
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
Oct 18, 199710.044NOYES
CVE-2013-4854HIGH
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.
Jul 29, 20137.835NONO
CVE-2016-4448CRITICAL
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Jun 9, 20169.834NONO
CVE-1999-0041HIGH
Buffer overflow in NLS (Natural Language Service).
Feb 13, 19977.534NOYES
CVE-2004-0891HIGH
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via
Jan 27, 200510.033NONO
CVE-2013-7171CRITICAL
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitr
Nov 21, 20199.831NONO
CVE-2004-0940HIGH
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via S
Feb 9, 20057.830NOYES
View all 59 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products59 CVEs
14%
22%
59%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (6.8%)
Network4 (6.8%)
Unknown51 (86.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (13.6%)
High0 (0.0%)
Unknown51 (86.4%)
User Interaction
None8 (13.6%)
Unknown51 (86.4%)
Required0 (0.0%)
Privileges Required
Low4 (6.8%)
High0 (0.0%)
None4 (6.8%)
Unknown51 (86.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (59 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
30.5% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Slackware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Slackware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Slackware's Products

View all 3 CNAs →

Top CWEs