cbcvebase.

Suse Linux Enterprise Server vulnerabilities

473 known vulnerabilities affecting suse/linux_enterprise_server.

Total CVEs
473
CISA KEV
18
actively exploited
Public exploits
55
Exploited in wild
25
Severity breakdown
CRITICAL117HIGH91MEDIUM214LOW51

Vulnerabilities

Page 21 of 24
CVE-2014-4655P4MEDIUMCVSS 4.9v102014-07-03
CVE-2014-4655 [MEDIUM] CWE-190 CVE-2014-4655: The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linu The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPL
nvd
CVE-2014-6505P4MEDIUMCVSS 4.0v122014-10-15
CVE-2014-6505 [MEDIUM] CVE-2014-6505: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:MEMORY STORAGE ENGINE.
nvd
CVE-2013-3809P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3809 [MEDIUM] CVE-2013-3809: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log.
nvd
CVE-2014-6564P4MEDIUMCVSS 4.0v122014-10-15
CVE-2014-6564 [MEDIUM] CVE-2014-6564: Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB FULLTEXT SEARCH DML.
nvd
CVE-2011-4127P4MEDIUMCVSS 4.6v102012-07-03
CVE-2011-4127 [MEDIUM] CWE-264 CVE-2011-4127: The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
nvd
CVE-2014-4653P4MEDIUMCVSS 4.6v102014-07-03
CVE-2014-4653 [MEDIUM] CWE-416 CVE-2014-4653: sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not e sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.
nvd
CVE-2012-1146P4MEDIUMCVSS 5.5v112012-05-17
CVE-2012-1146 [MEDIUM] CWE-476 CVE-2012-1146: The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold ev
nvd
CVE-2012-1090P4MEDIUMCVSS 5.5v112012-05-17
CVE-2012-1090 [MEDIUM] CWE-20 CVE-2012-1090: The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to ca The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
nvd
CVE-2013-3793P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3793 [MEDIUM] CVE-2013-3793: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
nvd
CVE-2013-3783P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3783 [MEDIUM] CVE-2013-3783: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Parser.
nvd
CVE-2009-2472P4MEDIUMCVSS 4.3v10v112009-07-22
CVE-2009-2472 [MEDIUM] CWE-79 CVE-2009-2472: Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
nvd
CVE-2016-0642P4MEDIUMCVSS 4.7v11v122016-04-21
CVE-2016-0642 [MEDIUM] CVE-2016-0642: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated.
nvd
CVE-2014-1874P4MEDIUMCVSS 4.9v102014-02-28
CVE-2014-1874 [MEDIUM] CWE-20 CVE-2014-1874: The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel befo The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context.
nvd
CVE-2013-3794P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3794 [MEDIUM] CVE-2013-3794: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
nvd
CVE-2014-6520P4MEDIUMCVSS 4.0v122014-10-15
CVE-2014-6520 [MEDIUM] CVE-2014-6520: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:DDL.
nvd
CVE-2011-3970P4MEDIUMCVSS 4.3v10v112012-02-09
CVE-2011-3970 [MEDIUM] CWE-125 CVE-2011-3970: libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of s libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-6501P4MEDIUMCVSS 4.6v11.02015-03-30
CVE-2013-6501 [MEDIUM] CWE-74 CVE-2013-6501: The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.
nvd
CVE-2015-4106P4MEDIUMCVSS 4.6v11v122015-06-03
CVE-2015-4106 [MEDIUM] CWE-863 CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through de QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
nvd
CVE-2014-1489P4MEDIUMCVSS 4.3v112014-02-06
CVE-2014-1489 [MEDIUM] CWE-264 CVE-2014-1489: Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on oth Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
nvd
CVE-2010-4169P4MEDIUMCVSS 4.9v112010-11-22
CVE-2010-4169 [MEDIUM] CWE-416 CVE-2010-4169: Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local use Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.
nvd
Suse Linux Enterprise Server vulnerabilities | cvebase