Skip to main content

Vendor/product archive

novell / suse_linux CVEs

Beta · best-effort

23 CVEs tagged to novell / suse_linux2 Critical, 5 High, 11 Medium, 5 Low, 0 Unrated.

CVE-2012-0414

Published Dec 2, 2013

Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4854

Published Jul 29, 2013

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9…

CVSS 7.8 · High

CVE-2011-0988

Published Apr 18, 2011

pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable dir…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3912

Published Jan 13, 2011

The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vecto…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3110

Published Oct 12, 2010

Multiple buffer overflows in the Novell Client novfs module for the Linux kernel in SUSE Linux Enterprise 11 SP1 and openSUSE 11.3 allow local users to gain privileges via unspeci…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1297

Published Oct 23, 2009

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitr…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4432

Published Aug 20, 2007

Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4394

Published Aug 17, 2007

Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows loca…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5229

Published Oct 10, 2006

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0803

Published Feb 23, 2006

The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YO…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4790

Published Dec 31, 2005

Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which migh…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4791

Published Dec 31, 2005

Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary co…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-3321

Published Oct 27, 2005

chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1