Suse Linux Enterprise Desktop vulnerabilities

460 known vulnerabilities affecting suse/linux_enterprise_desktop.

Total CVEs
460
CISA KEV
35
actively exploited
Public exploits
57
Exploited in wild
35
Severity breakdown
CRITICAL135HIGH109MEDIUM174LOW42

Vulnerabilities

Page 1 of 23
CVE-2025-32463HIGHCVSS 7.8KEVPoCv152025-06-30
CVE-2025-32463 [CRITICAL] CWE-829 CVE-2025-32463: Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
nvd
CVE-2022-27239HIGHCVSS 7.8v152022-04-27
CVE-2022-27239 [HIGH] CWE-787 CVE-2022-27239: In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-li In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
nvd
CVE-2021-4034HIGHCVSS 7.8KEVPoCv152022-01-28
CVE-2021-4034 [HIGH] CWE-787 CVE-2021-4034: A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec applicat A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variabl
nvd
CVE-2018-10195HIGHCVSS 7.1v122021-06-02
CVE-2018-10195 [HIGH] CWE-190 CVE-2018-10195: lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect lengt lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
nvd
CVE-2020-8018HIGHCVSS 7.8v152020-05-04
CVE-2020-8018 [HIGH] CWE-276 CVE-2020-8018: A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deploy A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to escalate to root due to a /etc directory owned by the user This issue affects: SUSE Linux Enterprise Server 15 SP1 SLES15-SP1-CAP-Deployment-BYOS version 1
nvd
CVE-2014-1947HIGHCVSS 7.8PoCv112020-02-17
CVE-2014-1947 [HIGH] CWE-787 CVE-2014-1947: Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and e Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
nvd
CVE-2006-7246MEDIUMCVSS 6.8v112020-01-27
CVE-2006-7246 [MEDIUM] CWE-295 CVE-2006-7246: NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
nvd
CVE-2015-5239MEDIUMCVSS 6.5v11v122020-01-23
CVE-2015-5239 [MEDIUM] CWE-835 CVE-2015-5239: Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial o Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
nvd
CVE-2019-11038MEDIUMCVSS 5.3v122019-06-19
CVE-2019-11038 [MEDIUM] CWE-457 CVE-2019-11038: When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the s
nvd
CVE-2017-16232HIGHCVSS 7.5v122019-03-21
CVE-2017-16232 [HIGH] CWE-772 CVE-2017-16232: LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of s LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue
nvd
CVE-2018-19540HIGHCVSS 8.8v122018-11-26
CVE-2018-19540 [HIGH] CWE-787 CVE-2018-19540: An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14 An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0
nvd
CVE-2018-19543HIGHCVSS 7.8v122018-11-26
CVE-2018-19543 [HIGH] CWE-125 CVE-2018-19543: An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the fu An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
nvd
CVE-2018-19541HIGHCVSS 8.8v122018-11-26
CVE-2018-19541 [HIGH] CWE-125 CVE-2018-19541: An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14 An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0
nvd
CVE-2018-19542MEDIUMCVSS 6.5v122018-11-26
CVE-2018-19542 [MEDIUM] CWE-476 CVE-2018-19542: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_de An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
nvd
CVE-2018-19539MEDIUMCVSS 6.5v122018-11-26
CVE-2018-19539 [MEDIUM] CWE-617 CVE-2018-19539: An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_rea An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.
nvd
CVE-2018-18873MEDIUMCVSS 5.5v122018-10-31
CVE-2018-18873 [MEDIUM] CWE-476 CVE-2018-18873: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_pu An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
nvd
CVE-2017-18017CRITICALCVSS 9.8v122018-01-03
CVE-2017-18017 [CRITICAL] CWE-416 CVE-2017-18017: The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
nvd
CVE-2017-17806HIGHCVSS 7.8v122017-12-20
CVE-2017-17806 [HIGH] CWE-787 CVE-2017-17806: The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executi
nvd
CVE-2017-17805HIGHCVSS 7.8v122017-12-20
CVE-2017-17805 [HIGH] CWE-20 CVE-2017-17805: The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-le The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified other impact by executing a crafted seq
nvd
CVE-2017-13082HIGHCVSS 8.1v122017-10-17
CVE-2017-13082 [HIGH] CWE-323 CVE-2017-13082: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwi Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
1 / 23Next →