Suse Linux Enterprise Server vulnerabilities
131 known vulnerabilities affecting suse/suse_linux_enterprise_server.
Total CVEs
131
CISA KEV
2
actively exploited
Public exploits
14
Exploited in wild
7
Severity breakdown
CRITICAL34HIGH51MEDIUM36LOW10
Vulnerabilities
Page 6 of 7
CVE-2019-15624P4MEDIUMCVSS 4.9v122020-02-04
CVE-2019-15624 [MEDIUM] CWE-20 CVE-2019-15624: Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
nvd
CVE-2018-20105P4MEDIUMCVSS 5.5v152020-01-27
CVE-2018-20105 [MEDIUM] CWE-532 CVE-2018-20105: A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterpris
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
nvd
CVE-2010-2537P4HIGHCVSS 7.1v112010-09-30
CVE-2010-2537 [HIGH] CVE-2010-2537: The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local us
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
nvd
CVE-2014-1530P4MEDIUMCVSS 6.1v10v112014-04-30
CVE-2014-1530 [MEDIUM] CWE-79 CVE-2014-1530: The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbir
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
nvd
CVE-2015-7976P4MEDIUMCVSS 4.3v122017-01-30
CVE-2015-7976 [MEDIUM] CWE-254 CVE-2015-7976: The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
nvd
CVE-2014-3610P4MEDIUMCVSS 5.5v112014-11-10
CVE-2014-3610 [MEDIUM] CVE-2014-3610: The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not
The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and
nvd
CVE-2010-2942P4MEDIUMCVSS 5.5v10v112010-09-21
CVE-2010-2942 [MEDIUM] CWE-401 CVE-2010-2942: The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-r
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gac
nvd
CVE-2010-3078P4MEDIUMCVSS 5.5v112010-09-21
CVE-2010-3078 [MEDIUM] CWE-200 CVE-2010-3078: The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.
nvd
CVE-2014-8559P4MEDIUMCVSS 5.5v112014-11-10
CVE-2014-8559 [MEDIUM] CWE-400 CVE-2014-8559: The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
nvd
CVE-2014-3647P4MEDIUMCVSS 5.5v112014-11-10
CVE-2014-3647 [MEDIUM] CVE-2014-3647: arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly per
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2014-1496P4MEDIUMCVSS 5.5v112014-03-19
CVE-2014-1496 [MEDIUM] CWE-269 CVE-2014-1496: Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey be
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
nvd
CVE-2010-2066P4MEDIUMCVSS 5.5v112010-09-08
CVE-2010-2066 [MEDIUM] CVE-2010-2066: The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
nvd
CVE-2014-3601P4MEDIUMCVSS 4.3v112014-09-01
CVE-2014-3601 [MEDIUM] CWE-189 CVE-2014-3601: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculate
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of s
nvd
CVE-2014-3646P4MEDIUMCVSS 5.5v112014-11-10
CVE-2014-3646 [MEDIUM] CVE-2014-3646: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit han
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2008-3275P4MEDIUMCVSS 5.5v102008-08-12
CVE-2008-3275 [MEDIUM] CWE-120 CVE-2008-3275: The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the L
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within dele
nvd
CVE-2007-6716P4MEDIUMCVSS 5.5v102008-09-04
CVE-2007-6716 [MEDIUM] CVE-2007-6716: fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
nvd
CVE-2015-0500P4MEDIUMCVSS 4.0v11.02015-04-16
CVE-2015-0500 [MEDIUM] CVE-2015-0500: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2015-0439P4MEDIUMCVSS 4.0v11.02015-04-16
CVE-2015-0439 [MEDIUM] CVE-2015-0439: Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3v10v112010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2014-8086P4MEDIUMCVSS 4.7v112014-10-13
CVE-2014-8086 [MEDIUM] CWE-362 CVE-2014-8086: Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
nvd