Suse

Linux Enterprise Server

474 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 16.38%
  • Veröffentlicht 17.04.2009 00:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 30.03.2009 16:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...

  • EPSS 0.59%
  • Veröffentlicht 25.03.2009 01:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...

  • EPSS 0.05%
  • Veröffentlicht 06.03.2009 11:30:02
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass...

  • EPSS 8.28%
  • Veröffentlicht 22.02.2009 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a cr...

  • EPSS 23.76%
  • Veröffentlicht 13.11.2008 11:30:01
  • Zuletzt bearbeitet 23.04.2026 00:35:47

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying pr...

  • EPSS 0.39%
  • Veröffentlicht 13.11.2008 01:00:01
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers t...

  • EPSS 0.09%
  • Veröffentlicht 08.08.2008 19:41:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different for...

  • EPSS 0.07%
  • Veröffentlicht 02.05.2008 16:05:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.

  • EPSS 4.9%
  • Veröffentlicht 19.03.2008 10:44:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."