VendorsSUSEsuse_linuxall versions
Vulnerabilities

SUSE SuSE Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

217CVEs
CVE-2004-1190
SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.
Published 2004-12-15 · Modified
2.1EPSS 0.004
CVE-2001-0914
Linux kernel before 2.4.11pre3 in multiple Linux distributions allows local users to cause a denial of service (crash) by starting the core vmlinux kernel, possibly related to poor error checking during ELF loading.
Published 2004-09-01 · Modified
2.1EPSS 0.004
CVE-2004-2097
Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/rates created by x11perfcomp, (4) /tmp/xf86debug.1.log created by xf86debug, (5) /tmp/.winpopup-new created by winpopup-send.sh, or (6) /tmp/initrd created by lvmcreate_initrd.
Published 2005-05-27 · Modified
2.1EPSS 0.004
CVE-2005-4789
resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, does not properly enforce class-specific exclude rules in some situations, which allows local users to bypass intended access restrictions for USB devices that set their class ID at the interface level.
Published 2006-04-26 · Modified
2.1EPSS 0.004
CVE-2005-4788
resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, allows local users to bypass access control rules for USB devices via "alternate syntax for specifying USB devices."
Published 2006-04-26 · Modified
2.1EPSS 0.004
CVE-2005-3147
StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
Published 2005-10-05 · Modified
2.1EPSS 0.004
CVE-2001-0178
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
Published 2001-05-07 · Modified
2.1EPSS 0.004
CVE-2005-3146
StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.
Published 2005-10-05 · Modified
2.1EPSS 0.004
CVE-2004-1237
Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.
Published 2005-01-20 · Modified
2.1EPSS 0.004
CVE-2003-1295
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."
Published 2006-02-28 · Modified
2.1EPSS 0.004
CVE-2007-4394
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via unknown vectors.
Published 2007-08-17 · Modified
2.1EPSS 0.004
CVE-2004-1895
YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.
Published 2005-05-10 · Modified
2.1EPSS 0.003
CVE-2000-0361
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
Published 2000-07-12 · Modified
2.1EPSS 0.003
CVE-2005-4778
The powersave daemon in SUSE Linux 10.0 before 20051007 has an unspecified "configuration problem," which allows local users to suspend the computer and possibly perform certain other unauthorized actions.
Published 2006-04-13 · Modified
2.1EPSS 0.003
CVE-2004-2658
resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login types.
Published 2006-04-26 · Modified
2.1EPSS 0.003
CVE-2001-0109
rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.
Published 2001-05-07 · Modified
1.22 PoCEPSS 0.008
CVE-2004-1191
Race condition in SuSE Linux 8.1 through 9.2, when run on SMP systems that have more than 4GB of memory, could allow local users to read unauthorized memory from "foreign memory pages."
Published 2004-12-15 · Modified
1.2EPSS 0.003
← Prev6 / 6