Slackware is a distribution of Linux that, despite a narrow product scope, holds a position among the more prominent distributions in the landscape and carries a noteworthy vulnerability footprint. The vendor's vulnerabilities span a moderate share of serious-severity outcomes and frequently acquire public exploit code, reflecting both the maturity and widespread deployment of the operating system across server and workstation environments. The recurring weakness classes—including improper input validation, double-free conditions, and incorrect buffer-size calculations—are endemic to the native codebases bundled in the distribution and recur across its core packages rather than concentrated in a single application. Defenders tracking this distribution should prioritize its advisory streams and patch cycles, as individual flaws can propagate across many downstream systems; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slackware over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3798CRITICAL Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an | Jul 16, 2007 | 9.8 | 78 | NO | YES |
CVE-1999-0368HIGH Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | Feb 9, 1999 | 10.0 | 60 | NO | YES |
CVE-2000-0844HIGH Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun | Nov 14, 2000 | 10.0 | 44 | NO | YES |
CVE-1999-0192HIGH Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. | Oct 18, 1997 | 10.0 | 44 | NO | YES |
CVE-2013-4854HIGH The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9. | Jul 29, 2013 | 7.8 | 35 | NO | NO |
CVE-2016-4448CRITICAL Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | Jun 9, 2016 | 9.8 | 34 | NO | NO |
CVE-1999-0041HIGH Buffer overflow in NLS (Natural Language Service). | Feb 13, 1997 | 7.5 | 34 | NO | YES |
CVE-2004-0891HIGH Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via | Jan 27, 2005 | 10.0 | 33 | NO | NO |
CVE-2013-7171CRITICAL Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitr | Nov 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2004-0940HIGH Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via S | Feb 9, 2005 | 7.8 | 30 | NO | YES |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slackware.
Media articles that mention a CVE ID that affects a product developed by Slackware — matched by CVE ID, not by vendor name.