Suse

Linux Enterprise Server

474 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 26.12%
  • Veröffentlicht 27.08.2009 17:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 18.08.2009 21:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...

  • EPSS 0.5%
  • Veröffentlicht 11.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...

  • EPSS 1.25%
  • Veröffentlicht 06.08.2009 15:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...

Medienbericht
  • EPSS 1.86%
  • Veröffentlicht 30.07.2009 19:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...

  • EPSS 0.7%
  • Veröffentlicht 22.07.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, re...

Exploit
  • EPSS 2.33%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of ...

Exploit
  • EPSS 89.51%
  • Veröffentlicht 17.04.2009 14:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

  • EPSS 0.09%
  • Veröffentlicht 17.04.2009 14:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.