Novell Suse Linux Enterprise Server vulnerabilities

91 known vulnerabilities affecting novell/suse_linux_enterprise_server.

Total CVEs
91
CISA KEV
0
Public exploits
13
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH28MEDIUM44LOW5

Vulnerabilities

Page 1 of 5
CVE-2020-8118MEDIUMCVSS 5.0v12.02020-02-04
CVE-2020-8118 [MEDIUM] CWE-918 CVE-2020-8118: An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
nvd
CVE-2015-6815LOWCVSS 3.5v11.0v12.02020-01-31
CVE-2015-6815 [LOW] CWE-835 CVE-2015-6815: The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process tran The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
nvd
CVE-2013-4357HIGHCVSS 7.5v11.02019-12-31
CVE-2013-4357 [HIGH] CWE-120 CVE-2013-4357: The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
nvd
CVE-2016-5759HIGHCVSS 7.8v12.02017-09-08
CVE-2016-5759 [HIGH] CWE-20 CVE-2016-5759: The mkdumprd script called "dracut" in the current working directory "." allows local users to trick The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
nvd
CVE-2017-1000366HIGHCVSS 7.8PoCv11.02017-06-19
CVE-2017-1000366 [HIGH] CWE-119 CVE-2017-1000366: glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate th glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploita
nvd
CVE-2016-9961CRITICALCVSS 9.8v12.02017-06-06
CVE-2016-9961 [CRITICAL] CWE-189 CVE-2016-9961: game-music-emu before 0.6.1 mishandles unspecified integer values. game-music-emu before 0.6.1 mishandles unspecified integer values.
nvd
CVE-2016-9960MEDIUMCVSS 5.5v12.02017-06-06
CVE-2016-9960 [MEDIUM] CWE-369 CVE-2016-9960: game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and proc game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
nvd
CVE-2017-7995LOWCVSS 3.8v11.02017-05-03
CVE-2017-7995 [LOW] CWE-200 CVE-2017-7995: Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, all Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
nvd
CVE-2016-7796MEDIUMCVSS 5.5v12.02016-10-13
CVE-2016-7796 [MEDIUM] CWE-20 CVE-2016-7796: The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service ( The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
nvd
CVE-2015-8919HIGHCVSS 7.5v12.02016-09-20
CVE-2015-8919 [HIGH] CWE-119 CVE-2015-8919: The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file.
nvd
CVE-2015-8918HIGHCVSS 7.5v12.02016-09-20
CVE-2015-8918 [HIGH] CWE-119 CVE-2015-8918: The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote atta The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."
nvd
CVE-2015-8921HIGHCVSS 7.5v12.02016-09-20
CVE-2015-8921 [HIGH] CWE-125 CVE-2015-8921: The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
nvd
CVE-2015-8922MEDIUMCVSS 5.5v12.02016-09-20
CVE-2015-8922 [MEDIUM] CWE-476 CVE-2015-8922: The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
nvd
CVE-2015-8920MEDIUMCVSS 5.5v12.02016-09-20
CVE-2015-8920 [MEDIUM] CWE-125 CVE-2015-8920: The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows r The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
nvd
CVE-2015-8924MEDIUMCVSS 5.5v12.02016-09-20
CVE-2015-8924 [MEDIUM] CWE-125 CVE-2015-8924: The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
nvd
CVE-2015-8923MEDIUMCVSS 6.5v12.02016-09-20
CVE-2015-8923 [MEDIUM] CWE-20 CVE-2015-8923: The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
nvd
CVE-2016-4997HIGHCVSS 7.8PoCv12.02016-07-03
CVE-2016-4997 [HIGH] CWE-264 CVE-2016-4997: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter su The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
nvd
CVE-2016-1583HIGHCVSS 7.8PoCv11.0v12.02016-06-27
CVE-2016-1583 [HIGH] CWE-119 CVE-2016-1583: The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allo The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
nvd
CVE-2016-2834HIGHCVSS 8.8v12.02016-06-13
CVE-2016-2834 [HIGH] CVE-2016-2834: Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-2815HIGHCVSS 8.8v12.02016-06-13
CVE-2016-2815 [HIGH] CWE-119 CVE-2016-2815: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd