Suse Linux vulnerabilities
193 known vulnerabilities affecting suse/suse_linux.
Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25
Vulnerabilities
Page 4 of 10
CVE-2004-0981P4CRITICALCVSS 10.0v8.0v8.1+4 more2005-02-09
CVE-2004-0981 [CRITICAL] CVE-2004-0981: Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to e
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
nvd
CVE-2004-0867P4HIGHCVSS 7.5v1.0v8+3 more2004-12-23
CVE-2004-0867 [HIGH] CWE-264 CVE-2004-0867: Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such a
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
nvd
CVE-2005-0005P4HIGHCVSS 7.5v8.0v8.1+4 more2005-05-02
CVE-2005-0005 [HIGH] CVE-2005-0005: Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allo
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
nvd
CVE-2000-1044P4CRITICALCVSS 10.0v6.2v6.3+2 more2000-12-11
CVE-2000-1044 [CRITICAL] CVE-2000-1044: Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating system
Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.
nvd
CVE-2003-1538P4MEDIUMCVSS 6.4v8v8.12003-12-31
CVE-2003-1538 [MEDIUM] CWE-20 CVE-2003-1538: susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not p
susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.
nvd
CVE-1999-0433P4MEDIUMCVSS 4.6PoCv5.1v5.2+2 more1999-03-21
CVE-1999-0433 [MEDIUM] CVE-1999-0433: XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in re
XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
nvd
CVE-1999-0409P4MEDIUMCVSS 4.6PoCv3.5v5.21999-03-04
CVE-1999-0409 [MEDIUM] CVE-1999-0409: Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.
Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.
nvd
CVE-2003-0847P4MEDIUMCVSS 4.6PoCv8.22003-11-17
CVE-2003-0847 [MEDIUM] CVE-2003-0847: SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitra
SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.
nvd
CVE-2001-0610P4MEDIUMCVSS 4.6PoCv7.02001-08-02
CVE-2001-0610 [MEDIUM] CVE-2001-0610: kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink
kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.
nvd
CVE-2005-0639P4HIGHCVSS 7.5v1.0v2.0+26 more2005-03-02
CVE-2005-0639 [HIGH] CVE-2005-0639: Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.
nvd
CVE-2000-0868P4MEDIUMCVSS 5.0v6.3v6.42000-11-14
CVE-2000-0868 [MEDIUM] CVE-2000-0868: The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
nvd
CVE-2004-0889P4CRITICALCVSS 10.0v8.0v8.1+4 more2005-01-27
CVE-2004-0889 [CRITICAL] CVE-2004-0889: Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow re
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
nvd
CVE-2004-0817P4HIGHCVSS 7.5v8.0v8.1+4 more2004-12-31
CVE-2004-0817 [HIGH] CVE-2004-0817: Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execut
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
nvd
CVE-2004-0064P4LOWCVSS 2.1PoCv9.02004-02-17
CVE-2004-0064 [LOW] CVE-2004-0064: The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrar
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.
nvd
CVE-2000-0293P4LOWCVSS 2.1PoCv6.0v6.1+3 more2000-05-02
CVE-2000-0293 [LOW] CVE-2000-0293: aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrar
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.
nvd
CVE-2000-0614P4CRITICALCVSS 10.0v6.3v6.42000-07-10
CVE-2000-0614 [CRITICAL] CVE-2000-0614: Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded
Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.
nvd
CVE-2001-0869P4HIGHCVSS 7.5v7.0v7.1+2 more2001-12-21
CVE-2001-0869 [HIGH] CVE-2001-0869: Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyr
Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.
nvd
CVE-2004-0914P4CRITICALCVSS 10.0v1.0v8+5 more2005-01-10
CVE-2004-0914 [CRITICAL] CVE-2004-0914: Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, inc
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (a
nvd
CVE-2005-0337P4HIGHCVSS 7.5v8.0v8.1+4 more2005-05-02
CVE-2005-0337 [HIGH] CVE-2005-0337: Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_rec
Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.
nvd
CVE-2007-0460P4CRITICALCVSS 10.0≤ 10.1v9.32007-01-24
CVE-2007-0460 [CRITICAL] CWE-119 CVE-2007-0460: Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions,
Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."
nvd