cbcvebase.

Suse Linux vulnerabilities

193 known vulnerabilities affecting suse/suse_linux.

Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25

Vulnerabilities

Page 5 of 10
CVE-2005-0605P4HIGHCVSS 7.5v6.1v6.2+12 more2005-03-02
CVE-2005-0605 [HIGH] CVE-2005-0605: scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value tha scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
nvd
CVE-2004-0554P4LOWCVSS 2.1PoCv7v8+5 more2004-08-06
CVE-2004-0554 [LOW] CVE-2004-0554: Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.
nvd
CVE-2005-0373P4HIGHCVSS 7.5v1.0v8.0+5 more2004-10-07
CVE-2005-0373 [HIGH] CVE-2005-0373: Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
nvd
CVE-2004-0991P4HIGHCVSS 7.5v8.0v8.1+4 more2005-01-11
CVE-2004-0991 [HIGH] CVE-2004-0991: Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via fram Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
nvd
CVE-2001-0109P4LOWCVSS 1.2PoCv6.1v6.2+3 more2001-03-12
CVE-2001-0109 [LOW] CVE-2001-0109: rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlin rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.
nvd
CVE-2004-0497P4LOWCVSS 2.1PoCv8.0v8.1+3 more2004-12-06
CVE-2004-0497 [LOW] CVE-2004-0497: Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, suc Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
nvd
CVE-2007-5196P4HIGHCVSS 7.5v102007-10-14
CVE-2007-5196 [HIGH] CVE-2007-5196: Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwi Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5195.
nvd
CVE-2002-0758P4HIGHCVSS 7.5v8.02002-08-12
CVE-2002-0758 [HIGH] CVE-2002-0758: ifup-dhcp script in the sysconfig package for SuSE 8.0 allows remote attackers to execute arbitrary ifup-dhcp script in the sysconfig package for SuSE 8.0 allows remote attackers to execute arbitrary commands via spoofed DHCP responses, which are stored and executed in a file.
nvd
CVE-2004-1005P4HIGHCVSS 7.5v8.0v8.1+4 more2005-04-14
CVE-2004-1005 [HIGH] CVE-2004-1005: Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to ha Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
nvd
CVE-2004-1073P4LOWCVSS 2.1PoCv1.0v8+5 more2005-01-10
CVE-2004-1073 [LOW] CVE-2004-1073: The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
nvd
CVE-2004-1004P4HIGHCVSS 7.5v8.0v8.1+4 more2005-04-14
CVE-2004-1004 [HIGH] CVE-2004-1004: Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote at Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
nvd
CVE-2004-0827P4HIGHCVSS 7.5v8.0v8.1+4 more2004-09-16
CVE-2004-0827 [HIGH] CVE-2004-0827: Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6 Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.
nvd
CVE-2004-1145P4MEDIUMCVSS 5.0v8.0v8.1+4 more2004-12-15
CVE-2004-1145 [MEDIUM] CVE-2004-1145: Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java c Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
nvd
CVE-2006-2658P4MEDIUMCVSS 5.0v9.2v9.3+2 more2006-09-12
CVE-2006-2658 [MEDIUM] CVE-2006-2658: Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request.
nvd
CVE-2007-5471P4HIGHCVSS 7.8v102007-10-16
CVE-2007-5471 [HIGH] CVE-2007-5471: libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 S libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request. NOTE: this issue probably affects other daemons that attempt to initialize this library within a chroot configuration or
nvd
CVE-2004-1098P4HIGHCVSS 7.5v8.0v8.1+4 more2005-01-10
CVE-2004-1098 [HIGH] CVE-2004-1098: MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.
nvd
CVE-2005-3625P4CRITICALCVSS 10.0v1.0v9.0+4 more2005-12-31
CVE-2005-3625 [CRITICAL] CWE-399 CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
nvd
CVE-2004-0866P4HIGHCVSS 7.5v1.0v8+3 more2004-09-16
CVE-2004-0866 [HIGH] CVE-2004-0866: Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such a Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-2004-0802P4MEDIUMCVSS 5.1v8.0v8.1+4 more2004-12-31
CVE-2004-0802 [MEDIUM] CVE-2004-0802: Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrar Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
nvd
CVE-2004-1176P4HIGHCVSS 7.5v8.0v8.1+4 more2005-04-14
CVE-2004-1176 [HIGH] CVE-2004-1176: Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
nvd
Suse Linux vulnerabilities | cvebase