Suse Linux Enterprise Desktop vulnerabilities

460 known vulnerabilities affecting suse/linux_enterprise_desktop.

Total CVEs
460
CISA KEV
35
actively exploited
Public exploits
59
Exploited in wild
35
Severity breakdown
CRITICAL135HIGH109MEDIUM174LOW42

Vulnerabilities

Page 21 of 23
CVE-2010-4158LOWCVSS 2.1PoCv10v112010-12-30
CVE-2010-4158 [LOW] CWE-200 CVE-2010-4158: The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check w The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.
nvd
CVE-2010-3874MEDIUMCVSS 4.0v112010-12-29
CVE-2010-3874 [MEDIUM] CWE-787 CVE-2010-3874: Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.
nvd
CVE-2010-4157MEDIUMCVSS 6.2v10v112010-12-10
CVE-2010-4157 [MEDIUM] CWE-190 CVE-2010-4157: Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.3 Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.
nvd
CVE-2010-3861LOWCVSS 2.1v112010-12-10
CVE-2010-3861 [LOW] CVE-2010-3861: The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not init The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.
nvd
CVE-2010-3904HIGHCVSS 7.8KEVPoCv112010-12-06
CVE-2010-3904 [HIGH] CWE-1284 CVE-2010-3904: The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol im The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
nvd
CVE-2010-4180MEDIUMCVSS 4.3v10v112010-12-06
CVE-2010-4180 [MEDIUM] CVE-2010-4180: OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enab OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
nvd
CVE-2010-4081LOWCVSS 1.9v102010-11-30
CVE-2010-4081 [LOW] CWE-909 CVE-2010-4081: The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSPM_IOCTL_GET_CONFIG_INFO ioctl call.
nvd
CVE-2010-4082LOWCVSS 1.9v112010-11-30
CVE-2010-4082 [LOW] CWE-909 CVE-2010-4082: The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6. The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a VIAFB_GET_INFO ioctl call.
nvd
CVE-2010-4080LOWCVSS 2.1v102010-11-30
CVE-2010-4080 [LOW] CWE-200 CVE-2010-4080: The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSP_IOCTL_GET_CONFIG_INFO ioctl call.
nvd
CVE-2010-4083LOWCVSS 1.9v10v112010-11-30
CVE-2010-4083 [LOW] CWE-909 CVE-2010-4083: The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC_STAT, or (4) SEM_STAT command in a semctl system call.
nvd
CVE-2010-4078LOWCVSS 1.9v102010-11-29
CVE-2010-4078 [LOW] CWE-909 CVE-2010-4078: The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FBIOGET_VBLANK ioctl call.
nvd
CVE-2010-4073LOWCVSS 1.9PoCv10v112010-11-29
CVE-2010-4073 [LOW] CWE-200 CVE-2010-4073: The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, whic The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3) compat_sys_shmctl functions in ipc/compat.c; and the (4) compat_sys_mq_open and (5) c
nvd
CVE-2010-4072LOWCVSS 1.9v10v112010-11-29
CVE-2010-4072 [LOW] CWE-200 CVE-2010-4072: The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initiali The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."
nvd
CVE-2010-2962HIGHCVSS 7.2v112010-11-26
CVE-2010-2962 [HIGH] CWE-20 CVE-2010-2962: drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via crafted use
nvd
CVE-2010-2963MEDIUMCVSS 6.2PoCv112010-11-26
CVE-2010-2963 [MEDIUM] CWE-20 CVE-2010-2963: drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kerne drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video devi
nvd
CVE-2010-4165MEDIUMCVSS 4.9PoCv112010-11-22
CVE-2010-4165 [MEDIUM] CWE-369 CVE-2010-4165: The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not prop The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, leading to a divide-by-zero error or incorrect use of a signed integer.
nvd
CVE-2010-4169MEDIUMCVSS 4.9v112010-11-22
CVE-2010-4169 [MEDIUM] CWE-416 CVE-2010-4169: Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local use Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.
nvd
CVE-2010-3442MEDIUMCVSS 4.7v102010-10-04
CVE-2010-3442 [MEDIUM] CWE-190 CVE-2010-3442: Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel b Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.
nvd
CVE-2010-3437MEDIUMCVSS 6.6PoCv10v112010-10-04
CVE-2010-3437 [MEDIUM] CWE-476 CVE-2010-3437: Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the L Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.
nvd
CVE-2010-3079MEDIUMCVSS 5.5v112010-09-30
CVE-2010-3079 [MEDIUM] CWE-476 CVE-2010-3079: kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properl kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set
nvd