Suse Linux vulnerabilities
193 known vulnerabilities affecting suse/suse_linux.
Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25
Vulnerabilities
Page 7 of 10
CVE-2005-1763P4HIGHCVSS 7.2v1.0v8+1 more2005-06-09
CVE-2005-1763 [HIGH] CVE-2005-1763: Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write b
Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.
nvd
CVE-2004-0496P4HIGHCVSS 7.2v7v82004-12-06
CVE-2004-0496 [HIGH] CVE-2004-0496: Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access
Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
nvd
CVE-2001-0918P4MEDIUMCVSS 5.1v7.2v7.32001-11-22
CVE-2001-0918 [MEDIUM] CVE-2001-0918: Vulnerabilities in CGI scripts in susehelp in SuSE 7.2 and 7.3 allow remote attackers to execute arb
Vulnerabilities in CGI scripts in susehelp in SuSE 7.2 and 7.3 allow remote attackers to execute arbitrary commands by not opening files securely.
nvd
CVE-2001-0525P4HIGHCVSS 7.2v6.3v6.4+1 more2001-08-14
CVE-2001-0525 [HIGH] CVE-2001-0525: Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating syst
Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument.
nvd
CVE-2004-1072P4HIGHCVSS 7.2v1.0v8+5 more2005-01-10
CVE-2004-1072 [HIGH] CVE-2004-1072: The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
nvd
CVE-2001-0834P4MEDIUMCVSS 6.4v6.3v6.4+4 more2001-12-06
CVE-2001-0834 [MEDIUM] CVE-2001-0834: htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c opt
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the targ
nvd
CVE-2002-0062P4HIGHCVSS 7.2v6.2v6.3+1 more2002-03-08
CVE-2002-0062 [HIGH] CWE-120 CVE-2002-0062: Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, all
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
nvd
CVE-2002-1285P4HIGHCVSS 7.2v7.0v7.1+4 more2002-11-29
CVE-2002-1285 [HIGH] CVE-2002-1285: runlpr in the LPRng package allows the local lp user to gain root privileges via certain command lin
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.
nvd
CVE-2005-0384P4MEDIUMCVSS 5.0v8.2v9.0+2 more2005-03-15
CVE-2005-0384 [MEDIUM] CVE-2005-0384: Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to caus
Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
nvd
CVE-2001-0851P4MEDIUMCVSS 5.0v6.3v6.4+4 more2001-12-06
CVE-2001-0851 [MEDIUM] CVE-2001-0851: Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rul
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.
nvd
CVE-2005-0470P4MEDIUMCVSS 5.0v9.22005-03-14
CVE-2005-0470 [MEDIUM] CVE-2005-0470: Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service
Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.
nvd
CVE-2006-2703P4MEDIUMCVSS 5.0v9.02006-06-01
CVE-2006-2703 [MEDIUM] CVE-2006-2703: The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows
The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows remote attackers to read network traffic and execute commands via a man-in-the-middle (MITM) attack.
nvd
CVE-2004-0957P4MEDIUMCVSS 6.8v8.0v8.1+4 more2005-02-09
CVE-2004-0957 [MEDIUM] CVE-2004-0957: Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
nvd
CVE-1999-0462P4HIGHCVSS 7.2v5.31999-03-17
CVE-1999-0462 [HIGH] CVE-1999-0462: suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users
suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.
nvd
CVE-2002-0854P4HIGHCVSS 7.2v7.3v8.02002-09-05
CVE-2002-0854 [HIGH] CVE-2002-0854: Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3
Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3, 8.0, and possibly other operating systems, may allow local users to gain privileges.
nvd
CVE-2005-4772P4MEDIUMCVSS 6.4v1.0v8+7 more2005-12-31
CVE-2005-4772 [MEDIUM] CVE-2005-4772: liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and o
liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.
nvd
CVE-2004-0905P4MEDIUMCVSS 4.6v1.0v8+4 more2004-09-14
CVE-2004-0905 [MEDIUM] CVE-2004-0905: Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
nvd
CVE-1999-1182P4HIGHCVSS 7.2v5.01997-07-17
CVE-1999-1182 [HIGH] CVE-1999-1182: Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local user
Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.
nvd
CVE-2004-0807P4MEDIUMCVSS 5.0v8v8.1+3 more2004-09-13
CVE-2004-0807 [MEDIUM] CVE-2004-0807: Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memo
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
nvd
CVE-2004-0886P4MEDIUMCVSS 5.0v1.0v8+4 more2005-01-27
CVE-2004-0886 [MEDIUM] CVE-2004-0886: Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
nvd