cbcvebase.

Suse Linux vulnerabilities

193 known vulnerabilities affecting suse/suse_linux.

Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25

Vulnerabilities

Page 2 of 10
CVE-2006-0745P4HIGHCVSS 7.2PoCv10.02006-03-21
CVE-2006-0745 [HIGH] CVE-2006-0745: X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
nvd
CVE-2005-0750P4HIGHCVSS 7.2PoCv1.0v9.32005-03-27
CVE-2005-0750 [HIGH] CVE-2005-0750: The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
nvd
CVE-1999-0768P4HIGHCVSS 7.5PoCv6.0v6.11999-08-25
CVE-1999-0768 [HIGH] CVE-1999-0768: Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable. Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
nvd
CVE-2004-1235P4MEDIUMCVSS 6.2PoCv1.0v8+5 more2005-04-14
CVE-2004-1235 [MEDIUM] CVE-2004-1235: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux ke Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
nvd
CVE-2000-0362P4HIGHCVSS 7.2PoCv6.1v6.21999-10-22
CVE-2000-0362 [HIGH] CVE-2000-0362: Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges. Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
nvd
CVE-2000-0229P4HIGHCVSS 7.2PoCv5.3v6.0+3 more2000-03-22
CVE-2000-0229 [HIGH] CVE-2000-0229: gpm-root in the gpm package does not properly drop privileges, which allows local users to gain priv gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.
nvd
CVE-2000-1095P4HIGHCVSS 7.2PoCv6.4v7.02001-01-09
CVE-2000-1095 [HIGH] CVE-2000-1095: modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary com modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
nvd
CVE-2001-0193P4HIGHCVSS 7.2PoCv6.3v6.4+1 more2001-05-03
CVE-2001-0193 [HIGH] CVE-2001-0193: Format string vulnerability in man in some Linux distributions allows local users to gain privileges Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
nvd
CVE-1999-0906P4HIGHCVSS 7.2PoCv6.21999-09-23
CVE-1999-0906 [HIGH] CVE-1999-0906: Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable. Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
nvd
CVE-2002-0004P4HIGHCVSS 7.2PoCv6.4v7.0+3 more2002-02-27
CVE-2002-0004 [HIGH] CVE-2002-0004: Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
nvd
CVE-2000-0231P4HIGHCVSS 7.2PoCv6.0v6.1+2 more2000-03-16
CVE-2000-0231 [HIGH] CVE-2000-0231: Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.
nvd
CVE-2004-2004P3CRITICALCVSS 10.0v9.12004-05-06
CVE-2004-2004 [CRITICAL] CVE-2004-2004: The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allo The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.
nvd
CVE-2000-0340P4HIGHCVSS 7.2PoCv6.3v6.42000-04-29
CVE-2000-0340 [HIGH] CVE-2000-0340: Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via t Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.
nvd
CVE-2000-0438P4HIGHCVSS 7.2PoCv4.2v4.3+12 more2000-05-22
CVE-2000-0438 [HIGH] CVE-2000-0438: Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbi Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.
nvd
CVE-2004-0461P3CRITICALCVSS 10.0v7v8+5 more2004-08-06
CVE-2004-0461 [CRITICAL] CVE-2004-0461: The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.
nvd
CVE-2004-0903P3CRITICALCVSS 10.0v1.0v8+4 more2005-01-27
CVE-2004-0903 [CRITICAL] CVE-2004-0903: Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
nvd
CVE-2004-0929P3CRITICALCVSS 10.0v1.0v8+4 more2005-01-27
CVE-2004-0929 [CRITICAL] CVE-2004-0929: Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earli Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.
nvd
CVE-2004-1154P3CRITICALCVSS 10.0v1.0v8.1+4 more2005-01-10
CVE-2004-1154 [CRITICAL] CVE-2004-1154: Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authe Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
nvd
CVE-2000-1016P4MEDIUMCVSS 5.0PoCv6.3v6.42000-12-11
CVE-2000-1016 [MEDIUM] CVE-2000-1016: The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc dire The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
nvd
CVE-2001-0172P4HIGHCVSS 7.2PoCv7.02001-03-26
CVE-2001-0172 [HIGH] CVE-2001-0172: Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.
nvd