Suse Linux Enterprise Server vulnerabilities
131 known vulnerabilities affecting suse/suse_linux_enterprise_server.
Total CVEs
131
CISA KEV
2
actively exploited
Public exploits
14
Exploited in wild
7
Severity breakdown
CRITICAL34HIGH51MEDIUM36LOW10
Vulnerabilities
Page 7 of 7
CVE-2015-5707P4MEDIUMCVSS 4.6v112015-10-19
CVE-2015-5707 [MEDIUM] CWE-190 CVE-2015-5707: Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
nvd
CVE-2015-2041P4MEDIUMCVSS 4.6v102015-04-21
CVE-2015-2041 [MEDIUM] CWE-17 CVE-2015-2041: net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl tab
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.
nvd
CVE-2010-2301P4MEDIUMCVSS 4.3v10v112010-06-15
CVE-2010-2301 [MEDIUM] CVE-2010-2301: Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.
nvd
CVE-2014-8134P4LOWCVSS 3.3v112014-12-12
CVE-2014-8134 [LOW] CVE-2014-8134: The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an im
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.
nvd
CVE-2018-6556P4LOWCVSS 3.3v112018-08-10
CVE-2018-6556 [LOW] CWE-417 CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). A
nvd
CVE-2015-3340P4LOWCVSS 2.9v11.0v122015-04-28
CVE-2015-3340 [LOW] CWE-200 CVE-2015-3340: Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service doma
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
nvd
CVE-2019-3687P4LOWCVSS 3.3≥ permissions, < 081d081dcfaf61710bda34bc21c80c66276119aa2020-01-24
CVE-2019-3687 [LOW] CWE-276 CVE-2019-3687: The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the
The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.
nvd
CVE-2014-0181P4LOWCVSS 2.1v112014-04-27
CVE-2014-0181 [LOW] CWE-264 CVE-2014-0181: The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for autho
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
nvd
CVE-2011-1585P4LOWCVSS 3.3v102013-06-08
CVE-2011-1585 [LOW] CWE-264 CVE-2011-1585: The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not prope
The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
nvd
CVE-2015-0413P4LOWCVSS 1.9v11.02015-01-21
CVE-2015-0413 [LOW] CVE-2015-0413: Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via
Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability.
nvd
CVE-2010-3881P4LOWCVSS 2.1v112010-12-23
CVE-2010-3881 [LOW] CWE-200 CVE-2010-3881: arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
nvd
← Previous7 / 7