Suse Linux Enterprise Software Development Kit vulnerabilities
35 known vulnerabilities affecting suse/suse_linux_enterprise_software_development_kit.
Total CVEs
35
CISA KEV
0
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL14HIGH10MEDIUM10LOW1
Vulnerabilities
Page 2 of 2
CVE-2014-1479P3HIGHCVSS 7.5v11.02014-02-06
CVE-2014-1479 [HIGH] CVE-2014-1479: The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.
nvd
CVE-2013-5615P3CRITICALCVSS 9.8v11.02013-12-11
CVE-2013-5615 [CRITICAL] CVE-2013-5615: The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderb
The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors.
nvd
CVE-2014-1481P3HIGHCVSS 7.5v11.02014-02-06
CVE-2014-1481 [HIGH] CVE-2014-1481: Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey be
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
nvd
CVE-2014-1487P3HIGHCVSS 7.5v11.02014-02-06
CVE-2014-1487 [HIGH] CWE-346 CVE-2014-1487: The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunder
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
nvd
CVE-2014-1497P3HIGHCVSS 8.8v11.02014-03-19
CVE-2014-1497 [HIGH] CWE-125 CVE-2014-1497: The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x b
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impac
nvd
CVE-2013-4419P4MEDIUMCVSS 6.8v11.02013-11-05
CVE-2013-4419 [MEDIUM] CWE-264 CVE-2013-4419: The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --liste
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance
nvd
CVE-2013-6673P4MEDIUMCVSS 5.9v11.02013-12-11
CVE-2013-6673 [MEDIUM] CWE-310 CVE-2013-6673: Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey be
Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that is unacceptable to the user.
nvd
CVE-2013-1864P4MEDIUMCVSS 4.3v11.02014-05-23
CVE-2013-1864 [MEDIUM] CWE-119 CVE-2013-1864: The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not proper
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."
nvd
CVE-2014-1483P4MEDIUMCVSS 5.0v11.02014-02-06
CVE-2014-1483 [MEDIUM] CWE-1021 CVE-2014-1483: Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Orig
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
nvd
CVE-2015-8845P4MEDIUMCVSS 5.5v12.02016-04-27
CVE-2015-8845 [MEDIUM] CWE-284 CVE-2015-8845: The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.
nvd
CVE-2014-1496P4MEDIUMCVSS 5.5v11.02014-03-19
CVE-2014-1496 [MEDIUM] CWE-269 CVE-2014-1496: Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey be
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
nvd
CVE-2015-0500P4MEDIUMCVSS 4.0v11.02015-04-16
CVE-2015-0500 [MEDIUM] CVE-2015-0500: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2015-0439P4MEDIUMCVSS 4.0v11.02015-04-16
CVE-2015-0439 [MEDIUM] CVE-2015-0439: Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756.
nvd
CVE-2016-3951P4MEDIUMCVSS 4.6v12.02016-05-02
CVE-2016-3951 [MEDIUM] CVE-2016-3951: Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physica
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.
nvd
CVE-2015-3340P4LOWCVSS 2.9v11.02015-04-28
CVE-2015-3340 [LOW] CWE-200 CVE-2015-3340: Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service doma
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
nvd
← Previous2 / 2