Suse
Suse Linux Enterprise: vulnerabilidades y CVE
Suse Linux Enterprise tiene 97 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE97
Últimos 12 meses0
Críticas3
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2009-4324 | Alta (7.8) | 82% | ⚠ Explotación activa | 15 dic 2009 | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code… |
| CVE-2009-3953 | Alta (8.8) | 83% | ⚠ Explotación activa | 13 ene 2010 | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document,… |
| CVE-2010-1297 | Alta (7.8) | 83% | ⚠ Explotación activa | 8 jun 2010 | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to… |
| CVE-2011-0609 | Alta (7.8) | 64% | ⚠ Explotación activa | 15 mar 2011 | Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-23301 | Media (5.5) | 0.29% | — | 12 ene 2024 | Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root. |
| CVE-2023-34256 | Media (5.5) | 0.25% | — | 31 may 2023 | An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE:… |
| CVE-2021-4028 | Alta (7.8) | 0.31% | — | 24 ago 2022 | A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after… |
| CVE-2021-41819 | Alta (7.5) | 2.9% | — | 1 ene 2022 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. |
| CVE-2021-41817 | Alta (7.5) | 3.2% | — | 1 ene 2022 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
| CVE-2021-4166 | Alta (7.1) | 1.6% | — | 25 dic 2021 | vim is vulnerable to Out-of-bounds Read |
| CVE-2020-14147 | Alta (7.7) | 3.1% | — | 15 jun 2020 | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and… |
| CVE-2018-14523 | Alta (8.8) | 2.0% | — | 23 jul 2018 | An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes. |
| CVE-2018-14522 | Alta (8.8) | 2.0% | — | 23 jul 2018 | An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes. |
| CVE-2016-9959 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. |
| CVE-2016-9958 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. |
| CVE-2016-9957 | Alta (7.8) | 1.9% | — | 12 abr 2017 | Stack-based buffer overflow in game-music-emu before 0.6.1. |
| CVE-2016-8569 | Media (5.5) | 1.8% | — | 3 feb 2017 | The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file. |
| CVE-2016-8568 | Media (5.5) | 1.9% | — | 3 feb 2017 | The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file. |
| CVE-2016-7966 | Alta (7.3) | 2.3% | — | 23 dic 2016 | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space… |
| CVE-2016-7099 | Media (5.9) | 2.8% | — | 10 oct 2016 | The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows… |
| CVE-2016-5325 | Media (6.1) | 4.1% | — | 10 oct 2016 | CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP… |
| CVE-2016-5131 | Alta (8.8) | 2.3% | — | 23 jul 2016 | Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to… |
| CVE-2016-2178 | Media (5.5) | 1.2% | — | 20 jun 2016 | The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a… |
| CVE-2016-1703 | Alta (8.8) | 1.2% | — | 5 jun 2016 | Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
| CVE-2016-1702 | Media (6.5) | 1.2% | — | 5 jun 2016 | The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service… |
| CVE-2016-1701 | Alta (8.8) | 0.95% | — | 5 jun 2016 | The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of… |
| CVE-2016-1700 | Alta (7.5) | 1.2% | — | 5 jun 2016 | extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of… |
| CVE-2016-1699 | Media (6.5) | 1.4% | — | 5 jun 2016 | WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated… |
| CVE-2016-1698 | Media (6.5) | 1.1% | — | 5 jun 2016 | The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary… |
| CVE-2016-1697 | Alta (8.8) | 1.8% | — | 5 jun 2016 | The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which… |
| CVE-2016-1696 | Alta (8.8) | 1.2% | — | 5 jun 2016 | The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
| CVE-2016-1695 | Alta (8.8) | 1.2% | — | 5 jun 2016 | Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
| CVE-2016-1694 | Media (5.3) | 1.0% | — | 5 jun 2016 | browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an… |
| CVE-2016-1693 | Media (5.3) | 1.2% | — | 5 jun 2016 | browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Suse
Linux Enterprise Server · 474Linux Enterprise Desktop · 461Linux Enterprise Software Development KIT · 296Suse Linux · 210Suse Linux Enterprise Server · 130Linux Enterprise Workstation Extension · 105Suse Linux Enterprise Desktop · 81Linux Enterprise Real Time Extension · 58Linux Enterprise Debuginfo · 54Rancher · 46Package HUB · 39Suse Linux Enterprise Software Development KIT · 35