cbcvebase.

Suse Linux vulnerabilities

193 known vulnerabilities affecting suse/suse_linux.

Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25

Vulnerabilities

Page 8 of 10
CVE-2005-4790P4MEDIUMCVSS 6.9v9.32005-12-31
CVE-2005-4790 [MEDIUM] CVE-2005-4790: Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distri Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
nvd
CVE-2005-1043P4MEDIUMCVSS 5.0v1.0v2.0+26 more2005-04-14
CVE-2005-1043 [MEDIUM] CVE-2005-1043: exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
nvd
CVE-2004-1093P4MEDIUMCVSS 5.0v8.0v8.1+4 more2005-04-14
CVE-2004-1093 [MEDIUM] CVE-2004-1093: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
nvd
CVE-2004-1092P4MEDIUMCVSS 5.0v8.0v8.1+4 more2005-04-14
CVE-2004-1092 [MEDIUM] CVE-2004-1092: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by c Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
nvd
CVE-2005-0085P4MEDIUMCVSS 6.8v8.0v8.1+4 more2005-04-27
CVE-2005-0085 [MEDIUM] CVE-2005-0085: Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
nvd
CVE-2001-1012P4HIGHCVSS 7.2v6.3v6.4+3 more2001-09-05
CVE-2001-1012 [HIGH] CVE-2001-1012: Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain r Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.
nvd
CVE-2004-0626P4MEDIUMCVSS 5.0v8.0v8.1+3 more2004-12-06
CVE-2004-0626 [MEDIUM] CVE-2004-0626: The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.
nvd
CVE-2004-1009P4MEDIUMCVSS 5.0v8.0v8.1+4 more2005-04-14
CVE-2004-1009 [MEDIUM] CVE-2004-1009: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (inf Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
nvd
CVE-2005-3624P4MEDIUMCVSS 5.0v1.0v9.0+4 more2005-12-31
CVE-2005-3624 [MEDIUM] CWE-189 CVE-2005-3624: The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, t The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
nvd
CVE-2006-0803P4MEDIUMCVSS 5.0v9.32006-02-23
CVE-2006-0803 [MEDIUM] CVE-2006-0803: The signature verification functionality in the YaST Online Update (YOU) script handling relies on a The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used.
nvd
CVE-2004-1091P4MEDIUMCVSS 5.0v8.0v8.1+4 more2005-04-14
CVE-2004-1091 [MEDIUM] CVE-2004-1091: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by t Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
nvd
CVE-2005-3626P4MEDIUMCVSS 5.0v1.0v9.0+4 more2005-12-31
CVE-2005-3626 [MEDIUM] CWE-399 CVE-2005-3626: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
nvd
CVE-2004-1142P4MEDIUMCVSS 5.0v8.0v8.1+4 more2004-12-15
CVE-2004-1142 [MEDIUM] CVE-2004-1142: Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.
nvd
CVE-2004-1090P4MEDIUMCVSS 5.0v8.0v8.1+4 more2005-04-14
CVE-2004-1090 [MEDIUM] CVE-2004-1090: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
nvd
CVE-2002-0762P4HIGHCVSS 7.2v8.02002-08-12
CVE-2002-0762 [HIGH] CVE-2002-0762: shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or as shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or assign extra group privileges to some users by changing filesize limits before calling programs that modify the files.
nvd
CVE-2006-0043P4MEDIUMCVSS 4.6v1.0v9.1+3 more2006-01-31
CVE-2006-0043 [MEDIUM] CVE-2006-0043: Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.
nvd
CVE-2006-0646P4MEDIUMCVSS 4.4v9.0v9.1+3 more2006-02-11
CVE-2006-0646 [MEDIUM] CVE-2006-0646: ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can l ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.
nvd
CVE-2004-0956P4MEDIUMCVSS 5.0v8.0v8.1+4 more2005-01-10
CVE-2004-0956 [MEDIUM] CVE-2004-0956: MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a M MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
nvd
CVE-2000-0363P4MEDIUMCVSS 6.2v6.1v6.21999-10-22
CVE-2000-0363 [MEDIUM] CVE-2000-0363: Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory. Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.
nvd
CVE-2004-0592P4MEDIUMCVSS 5.0v2.6.52004-12-31
CVE-2004-0592 [MEDIUM] CVE-2004-0592: The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type, a similar f
nvd
Suse Linux vulnerabilities | cvebase