Suse Linux vulnerabilities
193 known vulnerabilities affecting suse/suse_linux.
Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25
Vulnerabilities
Page 3 of 10
CVE-1999-0363P4HIGHCVSS 7.2PoCv5.21999-02-02
CVE-1999-0363 [HIGH] CVE-1999-0363: SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
nvd
CVE-1999-0405P4HIGHCVSS 7.2PoCv4.2v4.3+8 more1999-02-18
CVE-1999-0405 [HIGH] CVE-1999-0405: A buffer overflow in lsof allows local users to obtain root privilege.
A buffer overflow in lsof allows local users to obtain root privilege.
nvd
CVE-2004-0803P3HIGHCVSS 7.5v1.0v8+4 more2004-12-23
CVE-2004-0803 [HIGH] CVE-2004-0803: Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, re
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
nvd
CVE-2004-0947P3CRITICALCVSS 10.0v9.0v9.1+1 more2005-02-09
CVE-2004-0947 [CRITICAL] CVE-2004-0947: Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an ar
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.
nvd
CVE-1999-0746P4MEDIUMCVSS 5.0PoCv4.4v4.4.1+7 more1999-08-16
CVE-1999-0746 [MEDIUM] CVE-1999-0746: A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a re
A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.
nvd
CVE-2006-5616P3CRITICALCVSS 10.0v9.2v9.3+2 more2006-10-31
CVE-2006-5616 [CRITICAL] CVE-2006-5616: Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attac
Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-0230P3HIGHCVSS 7.5v102010-01-22
CVE-2010-0230 [HIGH] CWE-264 CVE-2010-0230: SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all netwo
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
nvd
CVE-2000-1134P4HIGHCVSS 7.2PoCv7.02001-01-09
CVE-2000-1134 [HIGH] CVE-2000-1134: Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash,
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
nvd
CVE-2001-0641P4MEDIUMCVSS 4.6PoCv6.0v6.1+5 more2001-09-20
CVE-2001-0641 [MEDIUM] CVE-2001-0641: Buffer overflow in man program in various distributions of Linux allows local user to execute arbitr
Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option.
nvd
CVE-2004-0687P3HIGHCVSS 7.5v8v8.1+3 more2004-10-20
CVE-2004-0687 [HIGH] CVE-2004-0687: Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in cre
Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.
nvd
CVE-2005-0156P4LOWCVSS 2.1PoCv8.0v8.1+4 more2005-02-07
CVE-2005-0156 [LOW] CVE-2005-0156: Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sper
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
nvd
CVE-1999-0804P4MEDIUMCVSS 5.0PoCv6.11999-06-01
CVE-1999-0804 [MEDIUM] CVE-1999-0804: Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes,
Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
nvd
CVE-2005-3298P3HIGHCVSS 7.5v9.02005-10-23
CVE-2005-3298 [HIGH] CVE-2005-3298: Multiple buffer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary co
Multiple buffer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2004-0902P3CRITICALCVSS 10.0v1.0v8+4 more2005-01-27
CVE-2004-0902 [CRITICAL] CVE-2004-0902: Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII
nvd
CVE-2005-0638P3HIGHCVSS 7.5v1.0v2.0+26 more2005-03-02
CVE-2005-0638 [HIGH] CVE-2005-0638: xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via sh
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
nvd
CVE-2004-0888P4CRITICALCVSS 10.0v8.0v8.1+4 more2005-01-27
CVE-2004-0888 [CRITICAL] CVE-2004-0888: Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS,
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
nvd
CVE-2009-1648P3HIGHCVSS 7.5v112009-07-05
CVE-2009-1648 [HIGH] CWE-16 CVE-2009-1648: The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not e
The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.
nvd
CVE-2004-0688P3HIGHCVSS 7.5v8v8.1+3 more2004-10-20
CVE-2004-0688 [HIGH] CVE-2004-0688: Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmI
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
nvd
CVE-2000-0800P4CRITICALCVSS 10.0v6.1v6.2+2 more2000-10-20
CVE-2000-0800 [CRITICAL] CVE-2000-0800: String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linu
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.
nvd
CVE-2004-1175P3HIGHCVSS 7.5v8.0v8.1+4 more2005-04-14
CVE-2004-1175 [HIGH] CVE-2004-1175: fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure fil
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
nvd