Vulnerabilities > Suse > Suse Linux > 10

DATE CVE VULNERABILITY TITLE RISK
2010-01-22 CVE-2010-0230 Permissions, Privileges, and Access Controls vulnerability in Suse Opensuse and Suse Linux
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
network
low complexity
suse CWE-264
7.5
2008-03-06 CVE-2008-0883 Link Following vulnerability in Adobe Acrobat Reader 8.1.2
acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.
local
high complexity
suse adobe CWE-59
3.7
2007-11-02 CVE-2007-5197 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mono
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
network
low complexity
suse debian opensuse mono CWE-119
7.5
2007-10-16 CVE-2007-5471 Denial Of Service vulnerability in Suse Linux 10
libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request.
network
low complexity
suse
7.8
2007-10-14 CVE-2007-5196 Information Exposure vulnerability in Suse Linux 10
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5195.
network
low complexity
suse CWE-200
7.5
2007-10-14 CVE-2007-5195 Information Exposure vulnerability in Suse Linux 10
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5196.
network
suse CWE-200
6.8
2007-08-20 CVE-2007-4432 Local Security vulnerability in Linux
Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 allows local users to gain privileges via modified (a) LD_LIBRARY_PATH and (b) MONO_GAC_PREFIX environment variables.
local
low complexity
novell suse
4.6
2007-08-17 CVE-2007-4394 Local Security vulnerability in Linux Desktop
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via unknown vectors.
local
low complexity
novell suse
2.1
2007-05-14 CVE-2007-2654 Race Condition vulnerability in multiple products
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
4.4
2006-12-20 CVE-2006-6662 Local Security vulnerability in Suse products
Unspecified vulnerability in Linux User Management (novell-lum) on SUSE Linux Enterprise Desktop 10 and Open Enterprise Server 9, under unspecified conditions, allows local users to log in to the console without a password.
local
suse
4.1