cbcvebase.

Suse Linux vulnerabilities

193 known vulnerabilities affecting suse/suse_linux.

Total CVEs
193
CISA KEV
0
Public exploits
51
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH74MEDIUM66LOW25

Vulnerabilities

Page 9 of 10
CVE-2005-0398P4MEDIUMCVSS 5.0v9.1v9.22005-03-14
CVE-2005-0398 [MEDIUM] CVE-2005-0398: The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of servic The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
nvd
CVE-2000-1107P4MEDIUMCVSS 5.0v6.0v6.1+4 more2001-01-09
CVE-2000-1107 [MEDIUM] CVE-2000-1107: in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of servic in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.
nvd
CVE-2005-3322P4MEDIUMCVSS 5.0v9.02005-10-27
CVE-2005-3322 [MEDIUM] CVE-2005-3322: Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of se Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).
nvd
CVE-2005-3013P4MEDIUMCVSS 4.6v9.32005-09-21
CVE-2005-3013 [MEDIUM] CVE-2005-3013: Buffer overflow in liby2util in Yet another Setup Tool (YaST) for SuSE Linux 9.3 allows local users Buffer overflow in liby2util in Yet another Setup Tool (YaST) for SuSE Linux 9.3 allows local users to execute arbitrary code via a long Loc entry.
nvd
CVE-2007-4432P4MEDIUMCVSS 4.6v102007-08-20
CVE-2007-4432 [MEDIUM] CVE-2007-4432: Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 allows local users to gain privileges via modified (a) LD_LIBRARY_PATH and (b) MONO_GAC_PREFIX environment variables.
nvd
CVE-2004-1139P4MEDIUMCVSS 5.0v8.0v8.1+4 more2004-12-15
CVE-2004-1139 [MEDIUM] CVE-2004-1139: Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attacke Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).
nvd
CVE-2002-2185P4MEDIUMCVSS 4.9v6.4v7.0+4 more2002-12-31
CVE-2002-2185 [MEDIUM] CVE-2002-2185: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
nvd
CVE-2007-2654P4MEDIUMCVSS 4.4v1.0v8+1 more2007-05-14
CVE-2007-2654 [MEDIUM] CWE-362 CVE-2007-2654: xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
nvd
CVE-2004-1174P4MEDIUMCVSS 5.0v8.0v8.1+4 more2005-04-14
CVE-2004-1174 [MEDIUM] CVE-2004-1174: direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of servi direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
nvd
CVE-1999-0831P4MEDIUMCVSS 5.0v6.2v6.31999-11-19
CVE-1999-0831 [MEDIUM] CVE-1999-0831: Denial of service in Linux syslogd via a large number of connections. Denial of service in Linux syslogd via a large number of connections.
nvd
CVE-2000-0433P4MEDIUMCVSS 4.6v6.1v6.2+2 more2000-05-02
CVE-2000-0433 [MEDIUM] CVE-2000-0433: The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which all The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.
nvd
CVE-2003-0846P4MEDIUMCVSS 4.6v7.32003-11-17
CVE-2003-0846 [MEDIUM] CVE-2003-0846: SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arb SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.
nvd
CVE-2004-0535P4LOWCVSS 2.1v7v8+5 more2004-08-06
CVE-2004-0535 [LOW] CVE-2004-0535: The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before usin The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
nvd
CVE-2006-6662P4MEDIUMCVSS 4.1v102006-12-20
CVE-2006-6662 [MEDIUM] CWE-264 CVE-2006-6662: Unspecified vulnerability in Linux User Management (novell-lum) on SUSE Linux Enterprise Desktop 10 Unspecified vulnerability in Linux User Management (novell-lum) on SUSE Linux Enterprise Desktop 10 and Open Enterprise Server 9, under unspecified conditions, allows local users to log in to the console without a password.
nvd
CVE-2005-3321P4MEDIUMCVSS 4.6v9.0v9.1+2 more2005-10-27
CVE-2005-3321 [MEDIUM] CVE-2005-3321: chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modified by chkstat to use weaker permissions.
nvd
CVE-1999-0234P4MEDIUMCVSS 4.6v4.21996-10-08
CVE-1999-0234 [MEDIUM] CVE-1999-0234: Bash treats any character with a value of 255 as a command separator. Bash treats any character with a value of 255 as a command separator.
nvd
CVE-2005-1761P4LOWCVSS 2.1v1.0v8+4 more2005-08-05
CVE-2005-1761 [LOW] CWE-20 CVE-2005-1761: Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (k Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.
nvd
CVE-2005-1767P4LOWCVSS 2.1v1.0v8+4 more2005-08-05
CVE-2005-1767 [LOW] CVE-2005-1767: traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, whi traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).
nvd
CVE-2004-2097P4LOWCVSS 2.1v9.02004-12-31
CVE-2004-2097 [LOW] CVE-2004-2097: Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink atta Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/rates created by x11perfcomp, (4) /tmp/xf86debug.1.log created by xf86debug, (5) /tmp/.winpopup-new created by winpopup-send.sh, or (6) /tmp/initrd created by lvmcreat
nvd
CVE-2005-4788P4LOWCVSS 2.1v9.2v9.32005-12-31
CVE-2005-4788 [LOW] CVE-2005-4788: resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, allows local users to bypass acc resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, allows local users to bypass access control rules for USB devices via "alternate syntax for specifying USB devices."
nvd
Suse Linux vulnerabilities | cvebase