← Back

Suse Linux

suse_linux

Vendor: Suse • 208 CVEs

CVEs (208)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Suse
1Suse Linux
Apr 16, 2026
Aug 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using...Show more
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.Show less
2Kde
Suse
2Kde
Suse Linux
Apr 16, 2026
Aug 2, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.
4Debian
MandrakesoftRalf S. Engelschall+1 more
4Debian Linux
EperlMandrake Linux+1 more
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
3Freebsd
MandrakesoftSuse
3Freebsd
Mandrake LinuxSuse Linux
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
2Debian
Suse
2Debian Linux
Suse Linux
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
4Caldera
ConectivaMandrakesoft+1 more
5Linux
Mandrake LinuxMandrake Linux Corporate Server+2 more
Apr 16, 2026
Mar 26, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
2Hans Reiser
Suse
2Reiserfs
Suse Linux
Apr 16, 2026
Mar 26, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.
1Suse
1Suse Linux
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.
7Caldera
ConectivaHp+4 more
9Hp Ux
ImmunixLinux+6 more
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to over...Show more
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.Show less
1Suse
1Suse Linux
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.
5Conectiva
ImmunixMandrakesoft+2 more
5Immunix
LinuxLinux+2 more
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
1Suse
1Suse Linux
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.
1Suse
1Suse Linux
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.
1Suse
1Suse Linux
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HT...Show more
The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.Show less
2Apache
Suse
2Http Server
Suse Linux
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
2Apache
Suse
2Http Server
Suse Linux
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
13Caldera
ConectivaDebian+10 more
16Aix
Debian LinuxImmunix+13 more
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
1Suse
1Suse Linux
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.
5Conectiva
DebianRedhat+2 more
5Debian Linux
LinuxLinux+2 more
Apr 16, 2026
Jul 16, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
1Suse
1Suse Linux
Apr 16, 2026
Jul 10, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.