Skip to main content

Vendor archive

suse CVEs

Beta · best-effort

1,190 CVEs tagged to vendor suse245 Critical, 421 High, 419 Medium, 105 Low, 0 Unrated.

CVE-2008-0063

Published Mar 19, 2008

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attacke…

CVSS 7.5 · High

CVE-2008-0732

Published Feb 12, 2008

The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or direct…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6427

Published Jan 18, 2008

The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within mu…

CVSS 9.3 · Critical

CVE-2007-6167

Published Nov 29, 2007

Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 module in the current working direc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5471

Published Oct 16, 2007

libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5195

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5196

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4432

Published Aug 20, 2007

Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4393

Published Aug 17, 2007

The installation script for orarun on SUSE Linux before 20070810 places the oracle user into the disk group, which allows the local oracle user to read or write raw disk partition…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4394

Published Aug 17, 2007

Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows loca…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0460

Published Jan 24, 2007

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calcu…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5616

Published Oct 31, 2006

Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-2703

Published Jun 1, 2006

The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows remote attackers to read network traffic and execute commands via a man-in-the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 1,190 CVEsPage 40 of 48