Novell Suse Linux Enterprise Server vulnerabilities
91 known vulnerabilities affecting novell/suse_linux_enterprise_server.
Total CVEs
91
CISA KEV
0
Public exploits
14
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH28MEDIUM44LOW5
Vulnerabilities
Page 3 of 5
CVE-2016-2834P3HIGHCVSS 8.8v12.02016-06-13
CVE-2016-2834 [HIGH] CVE-2016-2834: Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-2728P3HIGHCVSS 7.5v11v12.02015-07-06
CVE-2015-2728 [HIGH] CVE-2015-2728: The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and
The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 misinterprets an unspecified IDBDatabase field as a pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors, r
nvd
CVE-2016-4486P4LOWCVSS 3.3PoCv11.0v12.02016-05-23
CVE-2016-4486 [LOW] CWE-200 CVE-2016-4486: The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
nvd
CVE-2015-8918P3HIGHCVSS 7.5v12.02016-09-20
CVE-2015-8918 [HIGH] CWE-119 CVE-2015-8918: The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote atta
The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."
nvd
CVE-2016-4913P3HIGHCVSS 7.8v11.02016-05-23
CVE-2016-4913 [HIGH] CWE-200 CVE-2016-4913: The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
nvd
CVE-2016-4805P3HIGHCVSS 7.8v11.0v12.02016-05-23
CVE-2016-4805 [HIGH] CWE-416 CVE-2016-4805: Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allow
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
nvd
CVE-2016-5759P3HIGHCVSS 7.8v12.02017-09-08
CVE-2016-5759 [HIGH] CWE-20 CVE-2016-5759: The mkdumprd script called "dracut" in the current working directory "." allows local users to trick
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
nvd
CVE-2015-2708P4HIGHCVSS 7.5v12.02015-05-14
CVE-2015-2708 [HIGH] CVE-2015-2708: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-2709P4HIGHCVSS 7.5v12.02015-05-14
CVE-2015-2709 [HIGH] CVE-2015-2709: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-4914P4MEDIUMCVSS 6.4v10.02012-06-21
CVE-2011-4914 [MEDIUM] CWE-20 CVE-2011-4914: The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data
The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.
nvd
CVE-2008-2931P4HIGHCVSS 7.8v10.02008-07-09
CVE-2008-2931 [HIGH] CWE-269 CVE-2008-2931: The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
nvd
CVE-2015-2739P4CRITICALCVSS 10.0v11v12.02015-07-06
CVE-2015-2739 [CRITICAL] CWE-119 CVE-2015-2739: The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8
The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2015-2713P4MEDIUMCVSS 6.8v12.02015-05-14
CVE-2015-2713 [MEDIUM] CVE-2015-2713: Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 3
Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence contain
nvd
CVE-2013-4419P4MEDIUMCVSS 6.8v11.02013-11-05
CVE-2013-4419 [MEDIUM] CWE-264 CVE-2013-4419: The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --liste
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance
nvd
CVE-2015-0410P4MEDIUMCVSS 5.0v12.02015-01-21
CVE-2015-0410 [MEDIUM] CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
nvd
CVE-2015-0400P4MEDIUMCVSS 5.0v12.02015-01-21
CVE-2015-0400 [MEDIUM] CVE-2015-0400: Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect c
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
nvd
CVE-2015-8923P4MEDIUMCVSS 6.5v12.02016-09-20
CVE-2015-8923 [MEDIUM] CWE-20 CVE-2015-8923: The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
nvd
CVE-2014-3690P4MEDIUMCVSS 5.5v11v12.02014-11-10
CVE-2014-3690 [MEDIUM] CWE-400 CVE-2014-3690: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does n
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC
nvd
CVE-2020-8118P4MEDIUMCVSS 5.0v12.02020-02-04
CVE-2020-8118 [MEDIUM] CWE-918 CVE-2020-8118: An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
nvd
CVE-2015-8924P4MEDIUMCVSS 5.5v12.02016-09-20
CVE-2015-8924 [MEDIUM] CWE-125 CVE-2015-8924: The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
nvd