Suse Linux Enterprise vulnerabilities
96 known vulnerabilities affecting suse/linux_enterprise.
Total CVEs
96
CISA KEV
4
actively exploited
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL3HIGH61MEDIUM32
Vulnerabilities
Page 2 of 5
CVE-2016-1697HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1697 [HIGH] CWE-284 CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used i
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2016-1674HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1674 [HIGH] CVE-2016-1674: The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the
The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1676HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1676 [HIGH] CWE-284 CVE-2016-1676: extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1678HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1678 [HIGH] CWE-119 CVE-2016-1678: objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not pro
objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-1673HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1673 [HIGH] CVE-2016-1673: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1675HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1675 [HIGH] CWE-284 CVE-2016-1675: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
nvd
CVE-2016-1683HIGHCVSS 7.5v12.02016-06-05
CVE-2016-1683 [HIGH] CWE-119 CVE-2016-1683: numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespa
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2016-1679HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1679 [HIGH] CVE-2016-1679: The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chro
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-1680HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1680 [HIGH] CWE-119 CVE-2016-1680: Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome befo
Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-1691HIGHCVSS 7.5v12.02016-06-05
CVE-2016-1691 [HIGH] CWE-119 CVE-2016-1691: Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.
nvd
CVE-2016-1695HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1695 [HIGH] CVE-2016-1695: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1701HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1701 [HIGH] CVE-2016-1701: The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
nvd
CVE-2016-1700HIGHCVSS 7.5v12.02016-06-05
CVE-2016-1700 [HIGH] CVE-2016-1700: extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not conside
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to extensions.
nvd
CVE-2016-1703HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1703 [HIGH] CVE-2016-1703: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1696HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1696 [HIGH] CWE-254 CVE-2016-1696: The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings ac
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1681HIGHCVSS 8.8v12.02016-06-05
CVE-2016-1681 [HIGH] CWE-119 CVE-2016-1681: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2016-1693MEDIUMCVSS 5.3v12.02016-06-05
CVE-2016-1693 [MEDIUM] CWE-284 CVE-2016-1693: browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the H
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.
nvd
CVE-2016-1687MEDIUMCVSS 6.5v12.02016-06-05
CVE-2016-1687 [MEDIUM] CWE-200 CVE-2016-1687: The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public e
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.
nvd
CVE-2016-1698MEDIUMCVSS 6.5v12.02016-06-05
CVE-2016-1698 [MEDIUM] CWE-200 CVE-2016-1698: The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
nvd
CVE-2016-1677MEDIUMCVSS 6.5v12.02016-06-05
CVE-2016-1677 [MEDIUM] CWE-200 CVE-2016-1677: uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorre
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
nvd