Suse
Suse Linux Enterprise Server: vulnerabilidades y CVE
Suse Linux Enterprise Server tiene 130 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 23 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE130
Últimos 12 meses0
Críticas23
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-3714 | Alta (8.4) | 97% | ⚠ Explotación activa | 5 may 2016 | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell… |
| CVE-2014-0196 | Media (5.5) | 22% | ⚠ Explotación activa | 7 may 2014 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-52869 | Media (6) | 0.25% | — | 8 ene 2025 | Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12… |
| CVE-2020-15707 | Media (6.4) | 1.6% | — | 29 jul 2020 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2… |
| CVE-2020-15706 | Media (6.4) | 0.98% | — | 29 jul 2020 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to… |
| CVE-2020-15705 | Media (6.4) | 1.4% | — | 29 jul 2020 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure… |
| CVE-2020-6449 | Alta (8.8) | 2.7% | — | 23 mar 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6429 | Alta (8.8) | 2.3% | — | 23 mar 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6428 | Alta (8.8) | 2.3% | — | 23 mar 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6427 | Alta (8.8) | 2.4% | — | 23 mar 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6426 | Media (6.5) | 2.9% | — | 23 mar 2020 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6424 | Alta (8.8) | 3.5% | — | 23 mar 2020 | Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6422 | Alta (8.8) | 2.4% | — | 23 mar 2020 | Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2019-15624 | Media (4.9) | 1.5% | — | 4 feb 2020 | Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. |
| CVE-2018-20105 | Media (5.5) | 0.43% | — | 27 ene 2020 | A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue… |
| CVE-2020-5504 | Alta (8.8) | 39% | — | 9 ene 2020 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker… |
| CVE-2019-3688 | Alta (7.1) | 0.34% | — | 7 oct 2019 | The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750… |
| CVE-2018-19655 | Alta (8.8) | 2.9% | — | 29 nov 2018 | A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or… |
| CVE-2018-12122 | Alta (7.5) | 41% | — | 28 nov 2018 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS… |
| CVE-2018-12116 | Alta (7.5) | 4.6% | — | 28 nov 2018 | Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be… |
| CVE-2018-19208 | Media (6.5) | 1.5% | — | 12 nov 2018 | In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h. |
| CVE-2018-19052 | Alta (7.5) | 14% | — | 7 nov 2018 | An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration… |
| CVE-2018-6556 | Baja (3.3) | 0.33% | — | 10 ago 2018 | lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise… |
| CVE-2011-4190 | Media (5.3) | 0.78% | — | 8 jun 2018 | The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump… |
| CVE-2011-3172 | Crítica (9.8) | 1.0% | — | 8 jun 2018 | A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12. |
| CVE-2017-14798 | Alta (7) | 1.00% | — | 1 mar 2018 | A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root. |
| CVE-2017-5753 | Media (5.6) | 94% | — | 4 ene 2018 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
| CVE-2015-3405 | Alta (7.5) | 5.3% | — | 9 ago 2017 | ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and… |
| CVE-2015-5300 | Alta (7.5) | 9.1% | — | 21 jul 2017 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time… |
| CVE-2016-9959 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. |
| CVE-2016-9958 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. |
| CVE-2016-9957 | Alta (7.8) | 1.9% | — | 12 abr 2017 | Stack-based buffer overflow in game-music-emu before 0.6.1. |
Otros productos de Suse
Linux Enterprise Server · 474Linux Enterprise Desktop · 461Linux Enterprise Software Development KIT · 296Suse Linux · 210Linux Enterprise Workstation Extension · 105Linux Enterprise · 97Suse Linux Enterprise Desktop · 81Linux Enterprise Real Time Extension · 58Linux Enterprise Debuginfo · 54Rancher · 46Package HUB · 39Suse Linux Enterprise Software Development KIT · 35