Suse

Linux Enterprise Server

472 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Published 03.09.2010 20:00:03
  • Last modified 11.04.2025 00:51:21

The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file i...

Exploit
  • EPSS 4.09%
  • Published 30.07.2010 20:30:02
  • Last modified 11.04.2025 00:51:21

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a X...

Exploit
  • EPSS 17.03%
  • Published 30.06.2010 18:30:01
  • Last modified 11.04.2025 00:51:21

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

  • EPSS 1.57%
  • Published 30.06.2010 18:30:01
  • Last modified 11.04.2025 00:51:21

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

  • EPSS 0.61%
  • Published 27.05.2010 19:30:01
  • Last modified 11.04.2025 00:51:21

Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with ...

  • EPSS 2.2%
  • Published 19.05.2010 18:30:03
  • Last modified 11.04.2025 00:51:21

The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allo...

Exploit
  • EPSS 0.24%
  • Published 07.05.2010 18:30:01
  • Last modified 11.04.2025 00:51:21

Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact v...

  • EPSS 8.13%
  • Published 03.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which...

  • EPSS 12.31%
  • Published 09.01.2010 18:30:01
  • Last modified 09.04.2025 00:30:58

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) requ...

  • EPSS 0.07%
  • Published 20.11.2009 17:30:00
  • Last modified 09.04.2025 00:30:58

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.