cbcvebase.

Suse Linux vulnerabilities

193 known vulnerabilities affecting suse/suse_linux.

Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25

Vulnerabilities

Page 6 of 10
CVE-2005-2023P4CRITICALCVSS 10.0v9.32005-06-17
CVE-2005-2023 [CRITICAL] CVE-2005-2023: The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly hand The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.
nvd
CVE-2001-0458P4HIGHCVSS 7.5v6.3v6.4+2 more2001-06-27
CVE-2001-0458 [HIGH] CVE-2001-0458: Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arb Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
nvd
CVE-2004-0949P4MEDIUMCVSS 6.4v1.0v8+5 more2005-01-10
CVE-2004-0949 [MEDIUM] CVE-2004-0949: The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does n The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple t
nvd
CVE-2001-0388P4CRITICALCVSS 10.0v6.1v6.2+4 more2001-06-27
CVE-2001-0388 [CRITICAL] CVE-2001-0388: time server daemon timed allows remote attackers to cause a denial of service via malformed packets. time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
nvd
CVE-2005-0206P4HIGHCVSS 7.5v1.0v2.0+25 more2005-04-27
CVE-2005-0206 [HIGH] CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
nvd
CVE-2007-5195P4MEDIUMCVSS 6.8v102007-10-14
CVE-2007-5195 [MEDIUM] CWE-200 CVE-2007-5195: Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwi Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5196.
nvd
CVE-2000-1040P4CRITICALCVSS 10.0v6.2v6.3+2 more2000-12-11
CVE-2000-1040 [CRITICAL] CVE-2000-1040: Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks fi Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.
nvd
CVE-2002-0768P4HIGHCVSS 7.5v6.4v7.0+4 more2002-08-12
CVE-2002-0768 [HIGH] CVE-2002-0768: Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.
nvd
CVE-2004-0883P4MEDIUMCVSS 6.4v1.0v8+5 more2005-01-10
CVE-2004-0883 [MEDIUM] CVE-2004-0883: Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote sa Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_
nvd
CVE-2004-1184P4MEDIUMCVSS 4.6v1.0v2.0+25 more2005-01-21
CVE-2004-1184 [MEDIUM] CVE-2004-1184: The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
nvd
CVE-2004-1071P4HIGHCVSS 7.2v1.0v8+5 more2005-01-10
CVE-2004-1071 [HIGH] CVE-2004-1071: The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
nvd
CVE-2004-1476P4MEDIUMCVSS 5.1v8.0v8.1+4 more2004-12-31
CVE-2004-1476 [MEDIUM] CVE-2004-1476: Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived fr Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.
nvd
CVE-2004-0746P4HIGHCVSS 7.5v8v8.1+3 more2004-10-20
CVE-2004-0746 [HIGH] CVE-2004-0746: Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level do Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-1999-0434P4HIGHCVSS 7.5v5.31999-03-30
CVE-1999-0434 [HIGH] CVE-1999-0434: XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restr XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
nvd
CVE-2001-0872P4HIGHCVSS 7.2v6.4v7.0+3 more2001-12-21
CVE-2001-0872 [HIGH] CVE-2001-0872: OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment varia OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
nvd
CVE-2004-1070P4HIGHCVSS 7.2v1.0v8+5 more2005-01-10
CVE-2004-1070 [HIGH] CVE-2004-1070: The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4 The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
nvd
CVE-2004-0887P4HIGHCVSS 7.2v9.02005-01-27
CVE-2004-0887 [HIGH] CVE-2004-0887: SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged i SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.
nvd
CVE-2006-2752P4MEDIUMCVSS 6.4v9.02006-06-01
CVE-2006-2752 [MEDIUM] CVE-2006-2752: The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux Desktop 9 and SUSE SLES 9 has The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux Desktop 9 and SUSE SLES 9 has world-readable permissions, which allows attackers to obtain the rc (RedCarpet) password.
nvd
CVE-2000-0355P4HIGHCVSS 7.5v6.21999-08-21
CVE-2000-0355 [HIGH] CVE-2000-0355: pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files. pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.
nvd
CVE-2004-0495P4HIGHCVSS 7.2v7v8+5 more2004-08-06
CVE-2004-0495 [HIGH] CVE-2004-0495: Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.
nvd
Suse Linux vulnerabilities | cvebase