Slackware Linux

Vendor:

First CVE: Mar 1, 1995 · Active for 31 years

57
Total CVEs
More Total CVEs than 98% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Slackware Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 1995
31 years ago
Most Recent CVE
Nov 21, 2019
2,437 days ago

CVE Severity & Scoring

Slackware Linux57 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (5.3%)
Network3 (5.3%)
Unknown51 (89.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (10.5%)
High0 (0.0%)
Unknown51 (89.5%)
User Interaction
None6 (10.5%)
Unknown51 (89.5%)
Required0 (0.0%)
Privileges Required
Low3 (5.3%)
High0 (0.0%)
None3 (5.3%)
Unknown51 (89.5%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Feb 9, 199910.060NOYES
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun
Nov 14, 200010.044NOYES
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
Oct 18, 199710.044NOYES
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.
Jul 29, 20137.835NONO
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Jun 9, 20169.834NONO
Buffer overflow in NLS (Natural Language Service).
Feb 13, 19977.534NOYES
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via
Jan 27, 200510.033NONO
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitr
Nov 21, 20199.831NONO
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via S
Feb 9, 20057.830NOYES
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
Dec 15, 20037.530NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
29.8% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Slackware Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
current75.75.2%02
9.1155.83.8%03
9.0136.65.0%02
8.147.09.7%02
8.046.72.1%04
7.138.15.9%03
7.037.45.9%02
4.037.33.9%03
3.928.65.6%02
3.667.39.8%05
3.557.810.5%05
3.496.96.2%06
3.366.92.4%04
3.237.45.5%03
3.148.03.2%03
3.035.20.3%00
2.327.31.2%00
2.227.31.2%00
2.127.31.2%00
2.0.3517.20.3%00