VendorsSUSEsuse_linuxall versions
Vulnerabilities

SUSE SuSE Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

217CVEs
CVE-2002-0004
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
Published 2002-06-25 · Modified
7.21 PoCEPSS 0.013
CVE-2000-0340
Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.
Published 2000-10-13 · Modified
7.21 PoCEPSS 0.012
CVE-2001-0172
Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.
Published 2001-03-09 · Modified
7.21 PoCEPSS 0.012
CVE-2006-0745
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
Published 2006-03-21 · Modified
7.21 PoCEPSS 0.011
CVE-2000-1095
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
Published 2001-01-22 · Modified
7.21 PoCEPSS 0.011
CVE-2000-0438
Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.
Published 2000-07-12 · Modified
7.23 PoCEPSS 0.011
CVE-2001-0193
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.011
CVE-2001-0872
OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
Published 2002-06-25 · Modified
7.2EPSS 0.009
CVE-2000-0362
Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
Published 2000-07-12 · Modified
7.21 PoCEPSS 0.009
CVE-2005-0750
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
Published 2005-04-03 · Modified
7.24 PoCEPSS 0.008
CVE-2000-0218
Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.
Published 2000-04-10 · Modified
7.21 PoCEPSS 0.008
CVE-2000-0229
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.
Published 2000-06-02 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0906
Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
Published 2000-04-18 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0363
SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-2000-0231
Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.
Published 2000-06-02 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0405
A buffer overflow in lsof allows local users to obtain root privilege.
Published 1999-09-29 · Modified
7.22 PoCEPSS 0.008
CVE-2001-0525
Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument.
Published 2002-03-09 · Modified
7.2EPSS 0.006
CVE-2004-1072
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.
Published 2004-12-01 · Modified
7.2EPSS 0.006
CVE-2008-3949
emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute arbitrary code via a Trojan horse Python file.
Published 2008-09-22 · Modified
7.2EPSS 0.005
CVE-2004-1070
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
Published 2004-12-01 · Modified
7.2EPSS 0.005
CVE-2004-1071
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
Published 2004-12-01 · Modified
7.2EPSS 0.005
CVE-2002-0062
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
Published 2003-04-02 · Modified
7.2EPSS 0.005
CVE-2002-2259
Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors.
Published 2007-10-18 · Modified
7.2EPSS 0.005
CVE-1999-0390
Buffer overflow in Dosemu Slang library in Linux.
Published 2000-03-22 · Modified
7.2EPSS 0.004
CVE-2007-6167
Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 module in the current working directory.
Published 2007-11-29 · Modified
7.2EPSS 0.004
CVE-1999-1182
Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.
Published 2001-09-12 · Modified
7.2EPSS 0.004
CVE-2004-0495
Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.
Published 2004-06-23 · Modified
7.2EPSS 0.004
CVE-2005-1763
Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.
Published 2005-06-14 · Modified
7.2EPSS 0.004
CVE-1999-0462
suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.
Published 2000-02-04 · Modified
7.2EPSS 0.004
CVE-2004-0887
SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.
Published 2004-10-26 · Modified
7.2EPSS 0.004
CVE-2004-0496
Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
Published 2004-07-06 · Modified
7.2EPSS 0.004
CVE-2002-1285
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.
Published 2002-11-14 · Modified
7.2EPSS 0.004
CVE-2002-0762
shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or assign extra group privileges to some users by changing filesize limits before calling programs that modify the files.
Published 2003-04-02 · Modified
7.2EPSS 0.004
CVE-2002-0854
Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3, 8.0, and possibly other operating systems, may allow local users to gain privileges.
Published 2002-08-14 · Modified
7.2EPSS 0.003
CVE-2001-1012
Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.
Published 2002-02-02 · Modified
7.2EPSS 0.003
CVE-2005-4790
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
Published 2006-04-26 · Modified
6.9EPSS 0.005
CVE-2008-0411
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
Published 2008-02-28 · Modified
6.81 PoCEPSS 0.145
CVE-2004-0957
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
Published 2004-10-21 · Modified
6.8EPSS 0.024
CVE-2005-0085
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
Published 2005-02-15 · Modified
6.8EPSS 0.023
CVE-2007-5195
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5196.
Published 2007-10-14 · Modified
6.8EPSS 0.018
← Prev3 / 6Next →