Novell Suse Linux Enterprise Desktop vulnerabilities
83 known vulnerabilities affecting novell/suse_linux_enterprise_desktop.
Total CVEs
83
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
1
Severity breakdown
CRITICAL17HIGH23MEDIUM40LOW3
Vulnerabilities
Page 3 of 5
CVE-2016-4486P4LOWCVSS 3.3PoCv12.02016-05-23
CVE-2016-4486 [LOW] CWE-200 CVE-2016-4486: The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
nvd
CVE-2015-8918P3HIGHCVSS 7.5v12.02016-09-20
CVE-2015-8918 [HIGH] CWE-119 CVE-2015-8918: The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote atta
The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."
nvd
CVE-2016-4805P3HIGHCVSS 7.8v12.02016-05-23
CVE-2016-4805 [HIGH] CWE-416 CVE-2016-4805: Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allow
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
nvd
CVE-2016-5759P3HIGHCVSS 7.8v12.02017-09-08
CVE-2016-5759 [HIGH] CWE-20 CVE-2016-5759: The mkdumprd script called "dracut" in the current working directory "." allows local users to trick
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
nvd
CVE-2015-0406P3MEDIUMCVSS 5.8v11.02015-01-21
CVE-2015-0406 [MEDIUM] CVE-2015-0406: Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect c
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment.
nvd
CVE-2015-2708P4HIGHCVSS 7.5v12.02015-05-14
CVE-2015-2708 [HIGH] CVE-2015-2708: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-2709P4HIGHCVSS 7.5v12.02015-05-14
CVE-2015-2709 [HIGH] CVE-2015-2709: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2008-2931P4HIGHCVSS 7.8v10.02008-07-09
CVE-2008-2931 [HIGH] CWE-269 CVE-2008-2931: The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
nvd
CVE-2015-2739P4CRITICALCVSS 10.0v12.02015-07-06
CVE-2015-2739 [CRITICAL] CWE-119 CVE-2015-2739: The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8
The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2015-2713P4MEDIUMCVSS 6.8v12.02015-05-14
CVE-2015-2713 [MEDIUM] CVE-2015-2713: Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 3
Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence contain
nvd
CVE-2015-3044P4MEDIUMCVSS 5.0v11.0v12.02015-04-14
CVE-2015-3044 [MEDIUM] CWE-200 CVE-2015-3044: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
nvd
CVE-2015-0410P4MEDIUMCVSS 5.0v11.02015-01-21
CVE-2015-0410 [MEDIUM] CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
nvd
CVE-2015-0400P4MEDIUMCVSS 5.0v12.02015-01-21
CVE-2015-0400 [MEDIUM] CVE-2015-0400: Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect c
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
nvd
CVE-2015-8923P4MEDIUMCVSS 6.5v12.02016-09-20
CVE-2015-8923 [MEDIUM] CWE-20 CVE-2015-8923: The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
nvd
CVE-2014-3690P4MEDIUMCVSS 5.5v12.02014-11-10
CVE-2014-3690 [MEDIUM] CWE-400 CVE-2014-3690: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does n
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC
nvd
CVE-2015-8924P4MEDIUMCVSS 5.5v12.02016-09-20
CVE-2015-8924 [MEDIUM] CWE-125 CVE-2015-8924: The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
nvd
CVE-2015-8816P4MEDIUMCVSS 6.8v12.02016-04-27
CVE-2015-8816 [MEDIUM] CVE-2015-8816: The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not proper
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
nvd
CVE-2016-4482P4MEDIUMCVSS 6.2v12.02016-05-23
CVE-2016-4482 [MEDIUM] CWE-200 CVE-2016-4482: The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not i
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
nvd
CVE-2016-4569P4MEDIUMCVSS 5.5v12.02016-05-23
CVE-2016-4569 [MEDIUM] CWE-200 CVE-2016-4569: The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not in
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
nvd
CVE-2015-8920P4MEDIUMCVSS 5.5v12.02016-09-20
CVE-2015-8920 [MEDIUM] CWE-125 CVE-2015-8920: The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows r
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
nvd