Suse

Suse Linux Enterprise Desktop

82 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 08.09.2010 20:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.

  • EPSS 1.49%
  • Veröffentlicht 08.09.2010 20:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointe...

  • EPSS 0.08%
  • Veröffentlicht 08.09.2010 20:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local user...

  • EPSS 5.38%
  • Veröffentlicht 15.06.2010 18:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with sh...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 15.06.2010 18:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA ele...

  • EPSS 8.24%
  • Veröffentlicht 15.06.2010 18:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute...

  • EPSS 9.73%
  • Veröffentlicht 11.06.2010 19:30:20
  • Zuletzt bearbeitet 11.04.2025 00:51:21

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, wh...

Exploit
  • EPSS 3.44%
  • Veröffentlicht 04.11.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 22.10.2009 16:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.09.2008 17:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.