Novell
Novell Suse Linux Enterprise Server: vulnerabilidades y CVE
Novell Suse Linux Enterprise Server tiene 91 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE91
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-8118 | Media (5) | 1.3% | — | 4 feb 2020 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. |
| CVE-2015-6815 | Baja (3.5) | 0.98% | — | 31 ene 2020 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop… |
| CVE-2013-4357 | Alta (7.5) | 3.2% | — | 31 dic 2019 | The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. |
| CVE-2016-5759 | Alta (7.8) | 0.38% | — | 8 sept 2017 | The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root. |
| CVE-2017-1000366 | Alta (7.8) | 2.7% | — | 19 jun 2017 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional… |
| CVE-2016-9961 | Crítica (9.8) | 4.4% | — | 6 jun 2017 | game-music-emu before 0.6.1 mishandles unspecified integer values. |
| CVE-2016-9960 | Media (5.5) | 0.53% | — | 6 jun 2017 | game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). |
| CVE-2017-7995 | Baja (3.8) | 0.37% | — | 3 may 2017 | Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function.… |
| CVE-2016-7796 | Media (5.5) | 0.85% | — | 13 oct 2016 | The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the… |
| CVE-2015-8924 | Media (5.5) | 5.4% | — | 20 sept 2016 | The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file. |
| CVE-2015-8923 | Media (6.5) | 2.9% | — | 20 sept 2016 | The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. |
| CVE-2015-8922 | Media (5.5) | 2.1% | — | 20 sept 2016 | The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to… |
| CVE-2015-8921 | Alta (7.5) | 12% | — | 20 sept 2016 | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. |
| CVE-2015-8920 | Media (5.5) | 1.9% | — | 20 sept 2016 | The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. |
| CVE-2015-8919 | Alta (7.5) | 4.5% | — | 20 sept 2016 | The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file. |
| CVE-2015-8918 | Alta (7.5) | 3.8% | — | 20 sept 2016 | The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy." |
| CVE-2016-4997 | Alta (7.8) | 7.0% | — | 3 jul 2016 | The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory… |
| CVE-2016-1583 | Alta (7.8) | 1.4% | — | 27 jun 2016 | The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted… |
| CVE-2016-2834 | Alta (8.8) | 3.4% | — | 13 jun 2016 | Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified… |
| CVE-2016-2818 | Alta (8.8) | 3.9% | — | 13 jun 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or… |
| CVE-2016-2815 | Alta (8.8) | 2.9% | — | 13 jun 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code… |
| CVE-2016-0376 | Alta (8.1) | 5.7% | — | 3 jun 2016 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8… |
| CVE-2016-0363 | Alta (8.1) | 4.0% | — | 3 jun 2016 | The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8… |
| CVE-2016-4913 | Alta (7.8) | 0.51% | — | 23 may 2016 | The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from… |
| CVE-2016-4805 | Alta (7.8) | 0.48% | — | 23 may 2016 | Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have… |
| CVE-2016-4569 | Media (5.5) | 0.83% | — | 23 may 2016 | The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory… |
| CVE-2016-4486 | Baja (3.3) | 1.7% | — | 23 may 2016 | The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory… |
| CVE-2016-4485 | Alta (7.5) | 4.7% | — | 23 may 2016 | The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a… |
| CVE-2016-4482 | Media (6.2) | 0.55% | — | 23 may 2016 | The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory… |
| CVE-2016-3951 | Media (4.6) | 0.59% | — | 2 may 2016 | Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by… |
Otros productos de Novell
Suse Linux Enterprise Desktop · 83Groupwise · 75Netware · 72Suse Linux Enterprise Software Development KIT · 65Edirectory · 51Zenworks Configuration Management · 35Suse Linux Enterprise Real Time Extension · 33Iprint · 30Suse Linux Enterprise Workstation Extension · 24Suse Linux Enterprise Debuginfo · 24Suse Linux Enterprise Live Patching · 22Suse Linux Enterprise Module FOR Public Cloud · 22