← Back

Suse

suse

1,152 CVEs • 121 products

Products (121)

Click to collapse
Toggle
Suse Linux
suse_linux
Package Hub
package_hub
Rancher
rancher
Studio Onsite
studio_onsite
Manager
manager
Manager Proxy
manager_proxy
Caas Platform
caas_platform
Opensuse
opensuse
Webyast
webyast
Kiwi
kiwi
Rancher Fleet
rancher_fleet
Linux
linux
Cloud
cloud
Portus
portus
Backports
backports
Rancher Rke2
rancher_rke2
Wrangler
wrangler
Office Server
office_server
Suse Cvsup
suse_cvsup
Suse Iptables
suse_iptables
Yast2 Backup
yast2-backup
Vpnc
vpnc
Studio
studio
Opensuse Osc
opensuse_osc
Yast2
yast2
Opensuse Leap
opensuse_leap
Susefirewall2
susefirewall2
Shadow
shadow
Openqa
openqa
Trousers
trousers
Inn
inn
Mailman
mailman
Munin
munin
Yast2 Security
yast2-security
S390 Tools
s390-tools

CVEs (1,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
LinuxSuse
5Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+2 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a...Show more
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.Show less
4Canonical
LinuxSuse+1 more
6Esx
Linux Enterprise High Availability ExtensionLinux Kernel+3 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
4Canonical
LinuxOpensuse+1 more
5Linux Enterprise Desktop
Linux Enterprise ServerLinux Kernel+2 more
Apr 29, 2026
Sep 3, 2010
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NUL...Show more
The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via multiple unsuccessful calls to bind on an AF_IRDA (aka PF_IRDA) socket.Show less
4Canonical
DebianLinux+1 more
6Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+3 more
Apr 29, 2026
Sep 3, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read...Show more
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.Show less
3Mozilla
OpensuseSuse
7Firefox
Linux Enterprise DesktopLinux Enterprise Server+4 more
Apr 29, 2026
Jul 30, 2010
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a la...Show more
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.Show less
8Apple
CanonicalDebian+5 more
12Debian Linux
FedoraIphone Os+9 more
Apr 29, 2026
Jun 30, 2010
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Sca...Show more
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.Show less
10Apple
CanonicalDebian+7 more
17Chrome
Debian LinuxFedora+14 more
Apr 29, 2026
Jun 30, 2010
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data r...Show more
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.Show less
3Google
OpensuseSuse
4Chrome
OpensuseSuse Linux Enterprise Desktop+1 more
Apr 29, 2026
Jun 15, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remot...Show more
Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with shadow DOM trees, aka rdar problem 8007953. NOTE: this might overlap CVE-2010-1771.Show less
3Google
OpensuseSuse
4Chrome
OpensuseSuse Linux Enterprise Desktop+1 more
Apr 29, 2026
Jun 15, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerH...Show more
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.Show less
3Google
OpensuseSuse
4Chrome
OpensuseSuse Linux Enterprise Desktop+1 more
Apr 29, 2026
Jun 15, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that...Show more
rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table.Show less
5Apple
CanonicalGoogle+2 more
7Chrome
OpensuseSafari+4 more
Apr 29, 2026
Jun 11, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has...Show more
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."Show less
6Apache
CanonicalDebian+3 more
6Debian Linux
FedoraLinux Enterprise Desktop+3 more
Apr 29, 2026
Jun 10, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code e...Show more
OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.Show less
3Adobe
OpensuseSuse
5Acrobat
AirFlash Player+2 more
Apr 21, 2026
Jun 8, 2010
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute...Show more
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.Show less
5Canonical
FedoraprojectOpensuse+2 more
5Fedora
Linux Enterprise ServerOpensuse+2 more
Apr 29, 2026
May 27, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a...Show more
Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.Show less
7Canonical
DebianFedoraproject+4 more
7Database Server
Debian LinuxFedora+4 more
Apr 29, 2026
May 19, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for inva...Show more
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.Show less
3Opensuse
PhpSuse
3Linux Enterprise
OpensusePhp
Apr 29, 2026
May 7, 2010
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative ch...Show more
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed comparison, related to an integer overflow in the chunk size decoder.Show less
4Debian
LinuxOpensuse+1 more
6Debian Linux
Linux Enterprise DesktopLinux Enterprise High Availability Extension+3 more
Apr 29, 2026
May 7, 2010
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly h...Show more
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.Show less
5Canonical
FedoraprojectMit+2 more
5Fedora
Kerberos 5Linux Enterprise+2 more
Apr 29, 2026
Apr 7, 2010
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a ka...Show more
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.Show less
7Apple
CanonicalDebian+4 more
7Debian Linux
FedoraLibpng+4 more
Apr 29, 2026
Mar 3, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large unco...Show more
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.Show less
1Suse
2Opensuse
Suse Linux
Apr 29, 2026
Jan 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.