Slackware
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Slackware product.
RSS Feeds for Slackware security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Slackware products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Slackware Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Slackware. Slackware did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 6.50 |
| 2018 | 2 | 7.65 |
It may take a day or so for new Slackware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Slackware Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2019-11135 | Nov 14, 2019 |
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution mayTSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. |
|
| CVE-2018-9336 | May 01, 2018 |
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation. |
|
| CVE-2018-7184 | Mar 06, 2018 |
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, whichntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704. |
|
| CVE-2016-4448 | Jun 09, 2016 |
Format string vulnerability in libxml2 before 2.9.4Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. |
|
| CVE-2007-3798 | Jul 16, 2007 |
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlierInteger overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. |
|
| CVE-2004-0940 | Feb 09, 2005 |
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documentsBuffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error. |
|
| CVE-1999-0856 | Dec 01, 1999 |
login in Slackware 7.0login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist. |
|
| CVE-1999-0433 | Mar 21, 1999 |
XFree86 startx command is vulnerable to a symlink attackXFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. |
|
| CVE-1999-0368 | Feb 09, 1999 |
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.aBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. |
|
| CVE-1999-0341 | Jan 01, 1998 |
Buffer overflow in the Linux mail program "deliver"Buffer overflow in the Linux mail program "deliver" allows local users to gain root access. |
|