Suse Linux vulnerabilities
193 known vulnerabilities affecting suse/suse_linux.
Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25
Vulnerabilities
Page 2 of 10
CVE-2006-0745P4HIGHCVSS 7.2PoCv10.02006-03-21
CVE-2006-0745 [HIGH] CVE-2006-0745: X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
nvd
CVE-2005-0750P4HIGHCVSS 7.2PoCv1.0v9.32005-03-27
CVE-2005-0750 [HIGH] CVE-2005-0750: The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
nvd
CVE-1999-0768P4HIGHCVSS 7.5PoCv6.0v6.11999-08-25
CVE-1999-0768 [HIGH] CVE-1999-0768: Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
nvd
CVE-2004-1235P4MEDIUMCVSS 6.2PoCv1.0v8+5 more2005-04-14
CVE-2004-1235 [MEDIUM] CVE-2004-1235: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux ke
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
nvd
CVE-2000-0362P4HIGHCVSS 7.2PoCv6.1v6.21999-10-22
CVE-2000-0362 [HIGH] CVE-2000-0362: Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
nvd
CVE-2000-0229P4HIGHCVSS 7.2PoCv5.3v6.0+3 more2000-03-22
CVE-2000-0229 [HIGH] CVE-2000-0229: gpm-root in the gpm package does not properly drop privileges, which allows local users to gain priv
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.
nvd
CVE-2000-1095P4HIGHCVSS 7.2PoCv6.4v7.02001-01-09
CVE-2000-1095 [HIGH] CVE-2000-1095: modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary com
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
nvd
CVE-2001-0193P4HIGHCVSS 7.2PoCv6.3v6.4+1 more2001-05-03
CVE-2001-0193 [HIGH] CVE-2001-0193: Format string vulnerability in man in some Linux distributions allows local users to gain privileges
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
nvd
CVE-1999-0906P4HIGHCVSS 7.2PoCv6.21999-09-23
CVE-1999-0906 [HIGH] CVE-1999-0906: Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
nvd
CVE-2002-0004P4HIGHCVSS 7.2PoCv6.4v7.0+3 more2002-02-27
CVE-2002-0004 [HIGH] CVE-2002-0004: Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
nvd
CVE-2000-0231P4HIGHCVSS 7.2PoCv6.0v6.1+2 more2000-03-16
CVE-2000-0231 [HIGH] CVE-2000-0231: Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local
Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.
nvd
CVE-2004-2004P3CRITICALCVSS 10.0v9.12004-05-06
CVE-2004-2004 [CRITICAL] CVE-2004-2004: The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allo
The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.
nvd
CVE-2000-0340P4HIGHCVSS 7.2PoCv6.3v6.42000-04-29
CVE-2000-0340 [HIGH] CVE-2000-0340: Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via t
Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.
nvd
CVE-2000-0438P4HIGHCVSS 7.2PoCv4.2v4.3+12 more2000-05-22
CVE-2000-0438 [HIGH] CVE-2000-0438: Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbi
Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.
nvd
CVE-2004-0461P3CRITICALCVSS 10.0v7v8+5 more2004-08-06
CVE-2004-0461 [CRITICAL] CVE-2004-0461: The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.
nvd
CVE-2004-0903P3CRITICALCVSS 10.0v1.0v8+4 more2005-01-27
CVE-2004-0903 [CRITICAL] CVE-2004-0903: Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
nvd
CVE-2004-0929P3CRITICALCVSS 10.0v1.0v8+4 more2005-01-27
CVE-2004-0929 [CRITICAL] CVE-2004-0929: Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earli
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.
nvd
CVE-2004-1154P3CRITICALCVSS 10.0v1.0v8.1+4 more2005-01-10
CVE-2004-1154 [CRITICAL] CVE-2004-1154: Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authe
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
nvd
CVE-2000-1016P4MEDIUMCVSS 5.0PoCv6.3v6.42000-12-11
CVE-2000-1016 [MEDIUM] CVE-2000-1016: The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc dire
The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
nvd
CVE-2001-0172P4HIGHCVSS 7.2PoCv7.02001-03-26
CVE-2001-0172 [HIGH] CVE-2001-0172: Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and
Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.
nvd