Slocate
3 CVEs tracked since 2003. Since Feb 2003, none of them reached CISA KEV.
Slocate CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2003-02 | 1 | 0 |
| 2003-03 | null or fewer | |
| 2003-04 | null or fewer | |
| 2003-05 | 1 | 0 |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | null or fewer | |
| 2003-09 | null or fewer | |
| 2003-10 | 1 | 0 |
Products
The products that kept showing up in Slocate's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Slocate.
- CVE-2007-0227slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files. NOTE: another researcher ...5.0
- CVE-2005-2499slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory s...2.1
- CVE-2003-0848Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to ...4.6
- CVE-2003-0326Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to ma...4.6
- CVE-2003-0056Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.7.2
The record
- Peak rank
- #19 in Feb 2003
- Busiest month shown
- Feb 2003, 1 CVEs
- Months with a KEV entry
- 0 since Feb 2003
- Monthly snapshots
- 3 since 2003