Skip to main content

Vendor/product archive

suse / suse_linux CVEs

Beta · best-effort

215 CVEs tagged to suse / suse_linux30 Critical, 83 High, 70 Medium, 32 Low, 0 Unrated.

CVE-2024-12086

Published Jan 14, 2025

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a c…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2010-0230

Published Jan 22, 2010

SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access res…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1648

Published Jul 5, 2009

The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online upd…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3949

Published Sep 22, 2008

emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0732

Published Feb 12, 2008

The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or direct…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6167

Published Nov 29, 2007

Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 module in the current working direc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5471

Published Oct 16, 2007

libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5195

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5196

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4432

Published Aug 20, 2007

Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4393

Published Aug 17, 2007

The installation script for orarun on SUSE Linux before 20070810 places the oracle user into the disk group, which allows the local oracle user to read or write raw disk partition…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4394

Published Aug 17, 2007

Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows loca…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0460

Published Jan 24, 2007

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calcu…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5616

Published Oct 31, 2006

Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 215 CVEsPage 1 of 9