cbcvebase.

Suse Linux Enterprise Server vulnerabilities

473 known vulnerabilities affecting suse/linux_enterprise_server.

Total CVEs
473
CISA KEV
18
actively exploited
Public exploits
55
Exploited in wild
25
Severity breakdown
CRITICAL117HIGH91MEDIUM214LOW51

Vulnerabilities

Page 20 of 24
CVE-2018-18873P4MEDIUMCVSS 5.5v11v122018-10-31
CVE-2018-18873 [MEDIUM] CWE-476 CVE-2018-18873: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_pu An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
nvd
CVE-2016-0651P4MEDIUMCVSS 5.5v11v122016-04-21
CVE-2016-0651 [MEDIUM] CVE-2016-0651: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availabili Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors related to Optimizer.
nvd
CVE-2012-0879P4MEDIUMCVSS 5.5v112012-05-17
CVE-2012-0879 [MEDIUM] CWE-400 CVE-2012-0879: The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
nvd
CVE-2010-2538P4MEDIUMCVSS 5.5v112010-09-30
CVE-2010-2538 [MEDIUM] CWE-200 CVE-2010-2538: Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2. Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
nvd
CVE-2024-46955P4MEDIUMCVSS 5.5v122024-11-10
CVE-2024-46955 [MEDIUM] CWE-125 CVE-2024-46955: An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bo An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
nvd
CVE-2012-3992P4MEDIUMCVSS 4.3v10v112012-10-10
CVE-2012-3992 [MEDIUM] CWE-79 CVE-2012-3992: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and hi
nvd
CVE-2013-3802P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3802 [MEDIUM] CVE-2013-3802: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search.
nvd
CVE-2013-3804P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3804 [MEDIUM] CVE-2013-3804: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2014-6484P4MEDIUMCVSS 4.0v122014-10-15
CVE-2014-6484 [MEDIUM] CVE-2014-6484: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:DML.
nvd
CVE-2014-4287P4MEDIUMCVSS 4.0v122014-10-15
CVE-2014-4287 [MEDIUM] CVE-2014-4287: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS.
nvd
CVE-2012-3976P4MEDIUMCVSS 4.3v10v112012-08-29
CVE-2012-3976 [MEDIUM] CWE-200 CVE-2012-3976: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not proper Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
nvd
CVE-2014-4654P4MEDIUMCVSS 4.6v102014-07-03
CVE-2014-4654 [MEDIUM] CWE-416 CVE-2014-4654: The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linu The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a denial of service (use-after-free and system crash) by leveraging /dev/snd/controlCX access for
nvd
CVE-2017-5898P4MEDIUMCVSS 5.5v122017-03-15
CVE-2017-5898 [MEDIUM] CWE-190 CVE-2017-5898: Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emu Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.
nvd
CVE-2010-3079P4MEDIUMCVSS 5.5v112010-09-30
CVE-2010-3079 [MEDIUM] CWE-476 CVE-2010-3079: kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properl kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set
nvd
CVE-2023-23005P4MEDIUMCVSS 5.5v152023-03-01
CVE-2023-23005 [MEDIUM] CWE-476 CVE-2023-23005: In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value ( In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
nvd
CVE-2012-4194P4MEDIUMCVSS 4.3v10v112012-10-29
CVE-2012-4194 [MEDIUM] CWE-79 CVE-2012-4194: Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbi Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors inv
nvd
CVE-2014-2494P4MEDIUMCVSS 4.0v11v122014-07-17
CVE-2014-2494 [MEDIUM] CVE-2014-2494: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.
nvd
CVE-2012-4209P4MEDIUMCVSS 4.3v10v112012-11-21
CVE-2012-4209 [MEDIUM] CWE-79 CVE-2012-4209: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a b
nvd
CVE-2012-3994P4MEDIUMCVSS 4.3v10v112012-10-10
CVE-2012-3994 [MEDIUM] CWE-79 CVE-2012-3994: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the
nvd
CVE-2013-3808P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3808 [MEDIUM] CVE-2013-3808: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
nvd
Suse Linux Enterprise Server vulnerabilities | cvebase