Novell
Novell Suse Linux Enterprise Desktop: vulnerabilidades y CVE
Novell Suse Linux Enterprise Desktop tiene 83 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE83
Últimos 12 meses0
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-3043 | Crítica (9.8) | 74% | ⚠ Explotación activa | 14 abr 2015 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-6815 | Baja (3.5) | 0.98% | — | 31 ene 2020 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop… |
| CVE-2016-5759 | Alta (7.8) | 0.38% | — | 8 sept 2017 | The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root. |
| CVE-2017-1000366 | Alta (7.8) | 2.7% | — | 19 jun 2017 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional… |
| CVE-2016-9961 | Crítica (9.8) | 4.4% | — | 6 jun 2017 | game-music-emu before 0.6.1 mishandles unspecified integer values. |
| CVE-2016-9960 | Media (5.5) | 0.53% | — | 6 jun 2017 | game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). |
| CVE-2016-7796 | Media (5.5) | 0.85% | — | 13 oct 2016 | The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the… |
| CVE-2015-8924 | Media (5.5) | 5.4% | — | 20 sept 2016 | The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file. |
| CVE-2015-8923 | Media (6.5) | 2.9% | — | 20 sept 2016 | The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. |
| CVE-2015-8922 | Media (5.5) | 2.1% | — | 20 sept 2016 | The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to… |
| CVE-2015-8921 | Alta (7.5) | 12% | — | 20 sept 2016 | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. |
| CVE-2015-8920 | Media (5.5) | 1.9% | — | 20 sept 2016 | The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. |
| CVE-2015-8919 | Alta (7.5) | 4.5% | — | 20 sept 2016 | The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file. |
| CVE-2015-8918 | Alta (7.5) | 3.8% | — | 20 sept 2016 | The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy." |
| CVE-2016-4997 | Alta (7.8) | 7.0% | — | 3 jul 2016 | The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory… |
| CVE-2016-1583 | Alta (7.8) | 1.4% | — | 27 jun 2016 | The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted… |
| CVE-2016-2834 | Alta (8.8) | 3.4% | — | 13 jun 2016 | Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified… |
| CVE-2016-2818 | Alta (8.8) | 3.9% | — | 13 jun 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or… |
| CVE-2016-2815 | Alta (8.8) | 2.9% | — | 13 jun 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code… |
| CVE-2016-4805 | Alta (7.8) | 0.48% | — | 23 may 2016 | Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have… |
| CVE-2016-4569 | Media (5.5) | 0.83% | — | 23 may 2016 | The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory… |
| CVE-2016-4486 | Baja (3.3) | 1.7% | — | 23 may 2016 | The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory… |
| CVE-2016-4482 | Media (6.2) | 0.55% | — | 23 may 2016 | The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory… |
| CVE-2016-3951 | Media (4.6) | 0.59% | — | 2 may 2016 | Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by… |
| CVE-2016-3689 | Media (4.6) | 0.59% | — | 2 may 2016 | The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a… |
| CVE-2016-3140 | Media (4.6) | 1.8% | — | 2 may 2016 | The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a… |
| CVE-2016-3138 | Media (4.6) | 0.55% | — | 2 may 2016 | The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device… |
| CVE-2016-3137 | Media (4.6) | 0.55% | — | 2 may 2016 | drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an… |
| CVE-2016-3136 | Media (4.6) | 1.8% | — | 2 may 2016 | The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a… |
| CVE-2016-2188 | Media (4.6) | 1.8% | — | 2 may 2016 | The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted… |
| CVE-2016-2186 | Media (4.6) | 0.80% | — | 2 may 2016 | The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Novell
Suse Linux Enterprise Server · 91Groupwise · 75Netware · 72Suse Linux Enterprise Software Development KIT · 65Edirectory · 51Zenworks Configuration Management · 35Suse Linux Enterprise Real Time Extension · 33Iprint · 30Suse Linux Enterprise Workstation Extension · 24Suse Linux Enterprise Debuginfo · 24Suse Linux Enterprise Module FOR Public Cloud · 22Suse Linux Enterprise Live Patching · 22