Suse
Suse Linux Enterprise Desktop: vulnerabilidades y CVE
Suse Linux Enterprise Desktop tiene 461 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 26 son críticas y 36 figuran en el catálogo de explotación activa de CISA.
CVE461
Últimos 12 meses1
Críticas26
Explotadas activamente36
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2013-0648 | Alta (8.8) | 11% | ⚠ Explotación activa | 27 feb 2013 | Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before… |
| CVE-2014-0502 | Alta (8.8) | 25% | ⚠ Explotación activa | 21 feb 2014 | Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR… |
| CVE-2014-0497 | Crítica (9.8) | 100% | ⚠ Explotación activa | 5 feb 2014 | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via… |
| CVE-2013-0643 | Alta (8.8) | 11% | ⚠ Explotación activa | 27 feb 2013 | The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges,… |
| CVE-2010-3904 | Alta (7.8) | 14% | ⚠ Explotación activa | 6 dic 2010 | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which… |
| CVE-2016-3427 | Crítica (9.8) | 92% | ⚠ Explotación activa | 21 abr 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2014-3153 | Alta (7.8) | 37% | ⚠ Explotación activa | 7 jun 2014 | The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE… |
| CVE-2015-4495 | Alta (8.8) | 69% | ⚠ Explotación activa | 8 ago 2015 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via… |
| CVE-2015-8651 | Alta (8.8) | 68% | ⚠ Explotación activa | 28 dic 2015 | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe… |
| CVE-2015-5123 | Crítica (9.8) | 19% | ⚠ Explotación activa | 14 jul 2015 | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x… |
| CVE-2015-5122 | Crítica (9.8) | 94% | ⚠ Explotación activa | 14 jul 2015 | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x… |
| CVE-2015-3113 | Crítica (9.8) | 100% | ⚠ Explotación activa | 23 jun 2015 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via… |
| CVE-2015-0313 | Crítica (9.8) | 95% | ⚠ Explotación activa | 2 feb 2015 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via… |
| CVE-2015-0311 | Crítica (9.8) | 86% | ⚠ Explotación activa | 23 ene 2015 | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via… |
| CVE-2012-5076 | Crítica (9.8) | 91% | ⚠ Explotación activa | 16 oct 2012 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS. |
| CVE-2013-2465 | Crítica (9.8) | 99% | ⚠ Explotación activa | 18 jun 2013 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to… |
| CVE-2013-2729 | Crítica (9.8) | 67% | ⚠ Explotación activa | 16 may 2013 | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2022-27239 | Alta (7.8) | 0.58% | — | 27 abr 2022 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. |
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2018-10195 | Alta (7.1) | 0.39% | — | 2 jun 2021 | lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around. |
| CVE-2020-8018 | Alta (7.8) | 0.29% | — | 4 may 2020 | — |
| CVE-2014-1947 | Alta (7.8) | 7.0% | — | 17 feb 2020 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large… |
| CVE-2006-7246 | Media (6.8) | 0.88% | — | 27 ene 2020 | NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used. |
| CVE-2015-5239 | Media (6.5) | 3.6% | — | 23 ene 2020 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. |
| CVE-2019-11038 | Media (5.3) | 4.3% | — | 19 jun 2019 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible… |
| CVE-2017-16232 | Alta (7.5) | 5.6% | — | 21 mar 2019 | LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable… |
| CVE-2018-19543 | Alta (7.8) | 1.6% | — | 26 nov 2018 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. |
| CVE-2018-19542 | Media (6.5) | 1.9% | — | 26 nov 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service. |
| CVE-2018-19541 | Alta (8.8) | 2.8% | — | 26 nov 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25,… |
| CVE-2018-19540 | Alta (8.8) | 2.3% | — | 26 nov 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25,… |
| CVE-2018-19539 | Media (6.5) | 1.9% | — | 26 nov 2018 | An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service. |
| CVE-2018-18873 | Media (5.5) | 1.4% | — | 31 oct 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c. |
| CVE-2017-18017 | Crítica (9.8) | 53% | — | 3 ene 2018 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or… |
| CVE-2017-17806 | Alta (7.8) | 0.56% | — | 20 dic 2017 | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash… |
| CVE-2017-17805 | Alta (7.8) | 0.45% | — | 20 dic 2017 | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface… |
| CVE-2017-13088 | Media (5.3) | 1.8% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an… |
| CVE-2017-13087 | Media (5.3) | 1.7% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within… |
| CVE-2017-13086 | Media (6.8) | 2.0% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. |
| CVE-2017-13084 | Media (6.8) | 2.2% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof… |
| CVE-2017-13082 | Alta (8.1) | 4.6% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within… |
| CVE-2017-13081 | Media (5.3) | 2.0% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames… |
| CVE-2017-13080 | Media (5.3) | 2.3% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients. |
| CVE-2017-13079 | Media (5.3) | 2.1% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames… |
| CVE-2017-13078 | Media (5.3) | 2.1% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients. |
| CVE-2017-13077 | Media (6.8) | 2.4% | — | 17 oct 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Suse
Linux Enterprise Server · 474Linux Enterprise Software Development KIT · 296Suse Linux · 210Suse Linux Enterprise Server · 130Linux Enterprise Workstation Extension · 105Linux Enterprise · 97Suse Linux Enterprise Desktop · 81Linux Enterprise Real Time Extension · 58Linux Enterprise Debuginfo · 54Rancher · 46Package HUB · 39Suse Linux Enterprise Software Development KIT · 35