Suse Linux

Vendor:

First CVE: Oct 8, 1996 · Active for 29 years

217
Total CVEs
More Total CVEs than 100% of tracked products
13.6
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Suse Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 8, 1996
29 years ago
Most Recent CVE
Jan 14, 2025
556 days ago

CVE Severity & Scoring

Suse Linux217 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (0.5%)
Network5 (2.3%)
Unknown210 (96.8%)
Physical0 (0.0%)
Adjacent Network1 (0.5%)
Attack Complexity
Low5 (2.3%)
High2 (0.9%)
Unknown210 (96.8%)
User Interaction
None7 (3.2%)
Unknown210 (96.8%)
Required0 (0.0%)
Privileges Required
Low1 (0.5%)
High0 (0.0%)
None6 (2.8%)
Unknown210 (96.8%)

Top CVEs

Signals from CVEs in this product scope (217 CVEs).

217 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via
Jan 27, 20057.571NOYES
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Exp
May 14, 20097.256NOYES
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
Jul 16, 200010.052NOYES
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code
Mar 1, 200510.050NOYES
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
Jan 10, 200510.050NOYES
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
Nov 14, 20005.049NOYES
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and p
Aug 6, 200410.048NONO
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Mar 15, 20029.848NOYES
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
Mar 1, 19999.846NOYES
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun
Nov 14, 200010.044NOYES

Exploit Exposure

Signals from CVEs in this product scope (217 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
55 CVEs
25.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (217 CVEs).

Media Mentions

Signals from CVEs in this product scope (217 CVEs).

Top CNAs Publishing CVEs For Suse Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3225.91.9%01
9.2746.24.5%013
9.1806.44.1%09
9.0946.34.4%010
8.2746.44.9%010
8.1746.45.0%09
8.0526.44.4%06
8366.35.6%04
7.3206.63.4%03
7.2206.74.1%05
7.1226.84.1%06
7.0386.74.6%016
766.410.7%01
6.4406.97.6%017
6.3376.77.4%015
6.2316.65.2%014
6.1286.15.9%016
6.0225.86.0%014
5.3126.52.9%05
5.2126.12.9%07