Suse Linux Enterprise vulnerabilities
96 known vulnerabilities affecting suse/linux_enterprise.
Total CVEs
96
CISA KEV
4
actively exploited
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL3HIGH61MEDIUM32
Vulnerabilities
Page 2 of 5
CVE-2016-1974P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-1974 [HIGH] CWE-119 CVE-2016-1974: The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x be
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
nvd
CVE-2016-1676P3HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1676 [HIGH] CWE-284 CVE-2016-1676: extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-9958P3HIGHCVSS 7.8v12.02017-04-12
CVE-2016-9958 [HIGH] CWE-119 CVE-2016-9958: game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
nvd
CVE-2021-41819P3HIGHCVSS 7.5v11.0v12.0+1 more2022-01-01
CVE-2021-41819 [HIGH] CWE-565 CVE-2021-41819: CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affe
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
nvd
CVE-2016-9957P3HIGHCVSS 7.8v12.02017-04-12
CVE-2016-9957 [HIGH] CWE-119 CVE-2016-9957: Stack-based buffer overflow in game-music-emu before 0.6.1.
Stack-based buffer overflow in game-music-emu before 0.6.1.
nvd
CVE-2013-4480P3HIGHCVSS 7.5v11.02013-11-18
CVE-2013-4480 [HIGH] CWE-668 CVE-2013-4480: Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the firs
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
nvd
CVE-2016-7966P3HIGHCVSS 7.3v12.02016-12-23
CVE-2016-7966 [HIGH] CWE-94 CVE-2016-7966: Through a malicious URL that contained a quote character it was possible to inject HTML code in KMai
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicato
nvd
CVE-2016-1977P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-1977 [HIGH] CWE-119 CVE-2016-1977: The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozill
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font.
nvd
CVE-2016-2790P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-2790 [HIGH] CWE-19 CVE-2016-2790: The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
nvd
CVE-2016-2795P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-2795 [HIGH] CWE-19 CVE-2016-2795: The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefo
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
nvd
CVE-2018-14522P3HIGHCVSS 8.8v15.02018-07-23
CVE-2018-14522 [HIGH] CWE-119 CVE-2018-14522: An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pit
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.
nvd
CVE-2021-41817P3HIGHCVSS 7.5v12.0v15.02022-01-01
CVE-2021-41817 [HIGH] CWE-1333 CVE-2021-41817: Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
nvd
CVE-2016-2806P3HIGHCVSS 8.8v12.02016-04-30
CVE-2016-2806 [HIGH] CWE-119 CVE-2016-2806: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2016-2807P3HIGHCVSS 8.8v12.02016-04-30
CVE-2016-2807 [HIGH] CWE-119 CVE-2016-2807: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2016-1656P3HIGHCVSS 7.5v12.02016-04-18
CVE-2016-1656 [HIGH] CWE-284 CVE-2016-1656: The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.
nvd
CVE-2016-2797P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-2797 [HIGH] CWE-119 CVE-2016-2797: The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.
nvd
CVE-2016-2792P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-2792 [HIGH] CWE-119 CVE-2016-2792: The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Fir
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2800.
nvd
CVE-2016-2800P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-2800 [HIGH] CVE-2016-2800: The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Fir
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.
nvd
CVE-2016-2801P3HIGHCVSS 8.8v12.02016-03-13
CVE-2016-2801 [HIGH] CVE-2016-2801: The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.
nvd
CVE-2016-1655P3HIGHCVSS 8.8v12.02016-04-18
CVE-2016-1655 [HIGH] CVE-2016-1655: Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during cal
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extension.
nvd