Suse Linux Enterprise Server vulnerabilities
473 known vulnerabilities affecting suse/linux_enterprise_server.
Total CVEs
473
CISA KEV
18
actively exploited
Public exploits
55
Exploited in wild
25
Severity breakdown
CRITICAL117HIGH91MEDIUM214LOW51
Vulnerabilities
Page 22 of 24
CVE-2009-1072P4MEDIUMCVSS 4.9v102009-03-25
CVE-2009-1072 [MEDIUM] CWE-16 CVE-2009-1072: nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a us
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
nvd
CVE-2010-2954P4MEDIUMCVSS 4.9v112010-09-03
CVE-2010-2954 [MEDIUM] CWE-476 CVE-2010-2954: The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 doe
The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via multiple unsuccessful calls to bind on an AF_IRDA (ak
nvd
CVE-2013-3805P4MEDIUMCVSS 4.0v112013-07-17
CVE-2013-3805 [MEDIUM] CVE-2013-3805: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements.
nvd
CVE-2010-3442P4MEDIUMCVSS 4.7v9v102010-10-04
CVE-2010-3442 [MEDIUM] CWE-190 CVE-2010-3442: Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel b
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.
nvd
CVE-2014-4038P4MEDIUMCVSS 4.4v112014-06-17
CVE-2014-4038 [MEDIUM] CWE-59 CVE-2014-4038: ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1)
ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc and /tmp/diagSEsnap/snapH.tar.gz, or (3) lpd/test/lpd_ela_test.sh and /var/tmp/ras.
nvd
CVE-2010-4163P4MEDIUMCVSS 4.7v112011-01-03
CVE-2010-4163 [MEDIUM] CWE-20 CVE-2010-4163: The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local
The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.
nvd
CVE-2010-4162P4MEDIUMCVSS 4.7v10v112011-01-03
CVE-2010-4162 [MEDIUM] CWE-190 CVE-2010-4162: Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to caus
Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
nvd
CVE-2014-4656P4MEDIUMCVSS 4.6v102014-07-03
CVE-2014-4656 [MEDIUM] CWE-190 CVE-2014-4656: Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux k
Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl_add function and (2) numid values in the snd_ctl_remove_numid_conflict function.
nvd
CVE-2016-0668P4MEDIUMCVSS 4.1v122016-04-21
CVE-2016-0668 [MEDIUM] CVE-2016-0668: Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB.
nvd
CVE-2013-3812P4LOWCVSS 3.5v112013-07-17
CVE-2013-3812 [LOW] CVE-2013-3812: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
nvd
CVE-2010-3874P4MEDIUMCVSS 4.0v112010-12-29
CVE-2010-3874 [MEDIUM] CWE-787 CVE-2010-3874: Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager)
Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.
nvd
CVE-2010-3067P4MEDIUMCVSS 4.9v9v102010-09-21
CVE-2010-3067 [MEDIUM] CWE-190 CVE-2010-3067: Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next
Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.
nvd
CVE-2008-1945P4LOWCVSS 2.1v10v112008-08-08
CVE-2008-1945 [LOW] CVE-2008-1945: QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
nvd
CVE-2014-4214P4LOWCVSS 3.3v11.02014-07-17
CVE-2014-4214 [LOW] CVE-2014-4214: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows re
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP.
nvd
CVE-2014-4243P4LOWCVSS 2.8v112014-07-17
CVE-2014-4243 [LOW] CVE-2014-4243: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED.
nvd
CVE-2014-6463P4LOWCVSS 3.3v122014-10-15
CVE-2014-6463 [LOW] CVE-2014-6463: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML.
nvd
CVE-2014-6474P4LOWCVSS 3.5v122014-10-15
CVE-2014-6474 [LOW] CVE-2014-6474: Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:MEMCACHED.
nvd
CVE-2009-0834P4LOWCVSS 3.6v102009-03-06
CVE-2009-0834 [LOW] CVE-2009-0834: The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform doe
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
nvd
CVE-2014-0131P4LOWCVSS 2.9v112014-03-24
CVE-2014-0131 [LOW] CWE-416 CVE-2014-0131: Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel th
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
nvd
CVE-2014-1504P4LOWCVSS 2.6v112014-03-19
CVE-2014-1504 [LOW] CWE-264 CVE-2014-1504: The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consid
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.
nvd