Suse
Suse Linux Enterprise Software Development KIT: vulnerabilidades y CVE
Suse Linux Enterprise Software Development KIT tiene 296 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 23 son críticas y 11 figuran en el catálogo de explotación activa de CISA.
CVE296
Últimos 12 meses0
Críticas23
Explotadas activamente11
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-3427 | Crítica (9.8) | 92% | ⚠ Explotación activa | 21 abr 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
| CVE-2015-4495 | Alta (8.8) | 69% | ⚠ Explotación activa | 8 ago 2015 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via… |
| CVE-2013-1690 | Alta (8.8) | 69% | ⚠ Explotación activa | 26 jun 2013 | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which… |
| CVE-2013-2465 | Crítica (9.8) | 99% | ⚠ Explotación activa | 18 jun 2013 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to… |
| CVE-2012-1823 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 may 2012 | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote… |
| CVE-2012-0507 | Crítica (9.8) | 98% | ⚠ Explotación activa | 7 jun 2012 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect… |
| CVE-2015-4902 | Media (5.3) | 14% | ⚠ Explotación activa | 22 oct 2015 | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment. |
| CVE-2014-7169 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 sept 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
| CVE-2014-6271 | Crítica (9.8) | 100% | ⚠ Explotación activa | 24 sept 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by… |
| CVE-2016-3718 | Media (5.5) | 77% | ⚠ Explotación activa | 5 may 2016 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
| CVE-2016-3715 | Media (5.5) | 75% | ⚠ Explotación activa | 5 may 2016 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-1931 | Media (5.5) | 0.22% | — | 29 sept 2022 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information… |
| CVE-2022-27239 | Alta (7.8) | 0.58% | — | 27 abr 2022 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. |
| CVE-2020-8025 | Crítica (9.3) | 0.47% | — | 7 ago 2020 | A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap… |
| CVE-2014-1947 | Alta (7.8) | 7.0% | — | 17 feb 2020 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large… |
| CVE-2015-5239 | Media (6.5) | 3.6% | — | 23 ene 2020 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. |
| CVE-2019-11038 | Media (5.3) | 4.3% | — | 19 jun 2019 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible… |
| CVE-2017-16232 | Alta (7.5) | 5.6% | — | 21 mar 2019 | LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable… |
| CVE-2017-14804 | Media (5.3) | 1.7% | — | 1 mar 2018 | The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots. |
| CVE-2017-18017 | Crítica (9.8) | 53% | — | 3 ene 2018 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or… |
| CVE-2015-5300 | Alta (7.5) | 9.1% | — | 21 jul 2017 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time… |
| CVE-2017-1000366 | Alta (7.8) | 2.7% | — | 19 jun 2017 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional… |
| CVE-2016-4473 | Crítica (9.8) | 7.8% | — | 8 jun 2017 | /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833. |
| CVE-2015-8567 | Alta (7.7) | 5.6% | — | 13 abr 2017 | Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). |
| CVE-2016-9959 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. |
| CVE-2016-9958 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. |
| CVE-2016-9957 | Alta (7.8) | 1.9% | — | 12 abr 2017 | Stack-based buffer overflow in game-music-emu before 0.6.1. |
| CVE-2015-4680 | Alta (7.5) | 1.8% | — | 5 abr 2017 | FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates. |
| CVE-2016-7797 | Alta (7.5) | 3.3% | — | 24 mar 2017 | Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection. |
| CVE-2016-9398 | Alta (7.5) | 6.0% | — | 23 mar 2017 | The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors. |
| CVE-2014-9854 | Alta (7.5) | 3.7% | — | 17 mar 2017 | coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image." |
| CVE-2014-9853 | Media (5.5) | 1.8% | — | 17 mar 2017 | Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file. |
| CVE-2014-9852 | Crítica (9.8) | 2.9% | — | 17 mar 2017 | distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors. |
| CVE-2017-5898 | Media (5.5) | 0.40% | — | 15 mar 2017 | Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service… |
| CVE-2016-2318 | Media (5.5) | 1.9% | — | 3 feb 2017 | GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in… |
| CVE-2016-2317 | Media (5.5) | 2.0% | — | 3 feb 2017 | Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in… |
| CVE-2015-8934 | Media (5.5) | 2.3% | — | 20 sept 2016 | The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file. |
| CVE-2015-8933 | Media (5.5) | 2.0% | — | 20 sept 2016 | Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file. |
| CVE-2015-8932 | Media (5.5) | 2.2% | — | 20 sept 2016 | The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left… |
| CVE-2015-8931 | Alta (7.8) | 2.1% | — | 20 sept 2016 | Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted… |
| CVE-2015-8930 | Alta (7.5) | 4.3% | — | 20 sept 2016 | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself. |
Otros productos de Suse
Linux Enterprise Server · 474Linux Enterprise Desktop · 461Suse Linux · 210Suse Linux Enterprise Server · 130Linux Enterprise Workstation Extension · 105Linux Enterprise · 97Suse Linux Enterprise Desktop · 81Linux Enterprise Real Time Extension · 58Linux Enterprise Debuginfo · 54Rancher · 46Package HUB · 39Suse Linux Enterprise Software Development KIT · 35