Novell Suse Linux Enterprise Server vulnerabilities
91 known vulnerabilities affecting novell/suse_linux_enterprise_server.
Total CVEs
91
CISA KEV
0
Public exploits
14
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH28MEDIUM44LOW5
Vulnerabilities
Page 5 of 5
CVE-2016-2186P4MEDIUMCVSS 4.6v11.0v12.02016-05-02
CVE-2016-2186 [MEDIUM] CVE-2016-2186: The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allo
The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
nvd
CVE-2016-3689P4MEDIUMCVSS 4.6v12.02016-05-02
CVE-2016-3689 [MEDIUM] CVE-2016-3689: The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1
The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.
nvd
CVE-2016-3137P4MEDIUMCVSS 4.6v11.0v12.02016-05-02
CVE-2016-3137 [MEDIUM] CVE-2016-3137: drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attacke
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and cypress_open functions.
nvd
CVE-2012-6657P4MEDIUMCVSS 4.9v10.0v11.02014-09-28
CVE-2012-6657 [MEDIUM] CWE-264 CVE-2012-6657: The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure tha
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.
nvd
CVE-2016-2187P4MEDIUMCVSS 4.6v112016-05-02
CVE-2016-2187 [MEDIUM] CVE-2016-2187: The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows phys
The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
nvd
CVE-2016-3138P4MEDIUMCVSS 4.6v11.0v12.02016-05-02
CVE-2016-3138 [MEDIUM] CVE-2016-3138: The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physic
The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint descriptor.
nvd
CVE-2016-3951P4MEDIUMCVSS 4.6v12.02016-05-02
CVE-2016-3951 [MEDIUM] CVE-2016-3951: Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physica
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.
nvd
CVE-2015-6815P4LOWCVSS 3.5v11.0v12.02020-01-31
CVE-2015-6815 [LOW] CWE-835 CVE-2015-6815: The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process tran
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
nvd
CVE-2009-2707P4MEDIUMCVSS 4.9v102009-09-18
CVE-2009-2707 [MEDIUM] CVE-2009-2707: Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 i
Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 in SUSE Linux Enterprise (SLE) 10 SP2 on Itanium IA64 machines allows local users to cause a denial of service (system crash) via a 32-bit x86 application.
nvd
CVE-2017-7995P4LOWCVSS 3.8v11.02017-05-03
CVE-2017-7995 [LOW] CWE-200 CVE-2017-7995: Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, all
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
nvd
CVE-2012-2313P4LOWCVSS 1.2v10.02012-06-13
CVE-2012-2313 [LOW] CWE-264 CVE-2012-2313: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does no
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
nvd
← Previous5 / 5