Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Suse Linux HIGH 7.5
CVE-2009-1648

The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances invol…

Mitigation only
Fix from $1,950 2009-07-05
Yast2 Backup HIGH 7.2
CVE-2008-4636

yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by…

Fix: after 2.16.6
Fix from $1,950 2008-11-27
Suse Linux HIGH 7.2
CVE-2008-3949

emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which…

Mitigation only
Fix from $1,950 2008-09-22
Linux HIGH 7.5
CVE-2008-0063

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, wh…

Fix: 10.4.11 / 10.5.2+
Fix from $1,950 2008-03-19
Suse Linux HIGH 7.2
CVE-2007-6167

Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 modul…

Mitigation only
Fix from $1,950 2007-11-29
Suse Linux HIGH 7.8
CVE-2007-5471

libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, whi…

Patch available
Fix from $1,950 2007-10-16
Suse Linux HIGH 7.5
CVE-2007-5196

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…

Mitigation only
Fix from $1,950 2007-10-14
Suse Linux MEDIUM 6.8
CVE-2007-5195

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…

Patch available
Fix from $1,600 2007-10-14
Suse Linux HIGH 10.0
CVE-2007-0460

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to…

Fix: after 10.1
Fix from $1,950 2007-01-24
Suse Linux MEDIUM 6.4
CVE-2006-2752

The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux Desktop 9 and SUSE SLES 9 has world-readable permissions, which allows attacker…

Mitigation only
Fix from $1,600 2006-06-01
Suse Linux MEDIUM 5.0
CVE-2006-2703

The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows remote attackers to read network traffic and exe…

Mitigation only
Fix from $1,600 2006-06-01
Suse Linux Openexchange Server MEDIUM 6.4
CVE-2005-4772

liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which…

Patch available
Fix from $1,600 2005-12-31
Suse Linux HIGH 7.5
CVE-2005-3298

Multiple buffer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.

No fix yet
Fix from $1,950 2005-10-23
Suse Linux HIGH 10.0
CVE-2005-2023

The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry fr…

Patch available
Fix from $1,950 2005-06-17
Suse Linux MEDIUM 5.0
CVE-2004-0592

The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP optio…

Patch available
Fix from $1,600 2004-12-31
Suse Linux HIGH 10.0
CVE-2004-2004

The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.

Patch available
Fix from $1,950 2004-05-06
Suse Linux Openexchange Server MEDIUM 6.4
CVE-2003-1538

susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows…

Patch available
Fix from $1,600 2003-12-31
Suse Linux HIGH 7.2
CVE-2002-1285

runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.

Mitigation only
Fix from $1,950 2002-11-29
Suse Linux HIGH 7.2
CVE-2002-0854

Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3, 8.0, and possibly other operating systems, may …

Mitigation only
Fix from $1,950 2002-09-05
Suse Linux HIGH 7.5
CVE-2002-0758

ifup-dhcp script in the sysconfig package for SuSE 8.0 allows remote attackers to execute arbitrary commands via spoofed DHCP responses, which are st…

Patch available
Fix from $1,950 2002-08-12
Suse Linux HIGH 7.2
CVE-2002-0762

shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or assign extra group privileges to some users by chan…

Patch available
Fix from $1,950 2002-08-12
Suse Linux MEDIUM 5.1
CVE-2001-0918

Vulnerabilities in CGI scripts in susehelp in SuSE 7.2 and 7.3 allow remote attackers to execute arbitrary commands by not opening files securely.

Patch available
Fix from $1,600 2001-11-22
Suse Linux HIGH 7.2
CVE-2001-1012

Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under…

Mitigation only
Fix from $1,950 2001-09-05
Suse Linux HIGH 7.2
CVE-2001-0525

Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a …

Patch available
Fix from $1,950 2001-08-14
Suse Linux HIGH 7.5
CVE-2001-1130EPSS 11%

Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filename…

Patch available
Fix from $1,950 2001-08-02
Suse Linux MEDIUM 5.0
CVE-2000-1107

in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to …

Patch available
Fix from $1,600 2001-01-09
Suse Linux HIGH 10.0
CVE-2000-1040

Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a …

Patch available
Fix from $1,950 2000-12-11
Suse Linux HIGH 10.0
CVE-2000-1044

Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.

Patch available
Fix from $1,950 2000-12-11
Suse Linux MEDIUM 5.0
CVE-2000-1016EPSS 8%

The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read pack…

Patch available
Fix from $1,600 2000-12-11
Suse Linux HIGH 10.0
CVE-2000-0800

String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root pr…

Mitigation only
Fix from $1,950 2000-10-20