Slrn is a text-based Usenet newsreader with a narrow, specialized user base; its disclosures cluster around the threaded-reader application itself. The observed weakness signals remain general classification artifacts rather than concrete patterns, reflecting the small scale of the tracked vulnerability footprint. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slrn Development Team over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0740HIGH Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument. | Aug 12, 2002 | 7.2 | 27 | NO | YES |
CVE-2001-1035HIGH Binary decoding feature of slrn 0.9 and earlier allows remote attackers to execute commands via shell scripts that are inserted into a news post. | Sep 24, 2001 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slrn Development Team.
Media articles that mention a CVE ID that affects a product developed by Slrn Development Team — matched by CVE ID, not by vendor name.