Home/Product/suse linux enterprise
Product

suse linux enterprise

97 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-23301
all versions
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to
5.5MEDIUM
CVE-2023-34256
all versions
An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from
5.5MEDIUM
CVE-2021-4028
all versions
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to
7.8HIGH
CVE-2021-41819
all versions
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0
7.5HIGH
CVE-2021-41817
all versions
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed
7.5HIGH
CVE-2021-4166
all versions
vim is vulnerable to Out-of-bounds Read
7.1HIGH
CVE-2020-14147
all versions
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permissio
7.7HIGH
CVE-2018-14523
all versions
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstra
8.8HIGH
CVE-2018-14522
all versions
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubio
8.8HIGH
CVE-2016-9959
all versions
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
7.8HIGH
CVE-2016-9958
all versions
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
7.8HIGH
CVE-2016-9957
all versions
Stack-based buffer overflow in game-music-emu before 0.6.1.
7.8HIGH
CVE-2016-8569
all versions
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer
5.5MEDIUM
CVE-2016-8568
all versions
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bou
5.5MEDIUM
CVE-2016-7966
all versions
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to t
7.3HIGH
CVE-2016-7099
all versions
The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7
5.9MEDIUM
CVE-2016-5325
all versions
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x
6.1MEDIUM
CVE-2016-5131
all versions
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to ca
8.8HIGH
CVE-2016-2178
all versions
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time o
5.5MEDIUM
CVE-2016-1703
all versions
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly
8.8HIGH
CVE-2016-1702
all versions
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validat
6.5MEDIUM
CVE-2016-1701
all versions
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript c
8.8HIGH
CVE-2016-1700
all versions
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation
7.5HIGH
CVE-2016-1699
all versions
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome be
6.5MEDIUM
CVE-2016-1698
all versions
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2
6.5MEDIUM
CVE-2016-1697
all versions
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.27
8.8HIGH
CVE-2016-1696
all versions
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote atta
8.8HIGH
CVE-2016-1695
all versions
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly
8.8HIGH
CVE-2016-1694
all versions
browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which
5.3MEDIUM
CVE-2016-1693
all versions
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com
5.3MEDIUM
CVE-2016-1692
all versions
WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading
5.3MEDIUM
CVE-2016-1691
all versions
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial o
7.5HIGH
CVE-2016-1690
all versions
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript c
7.5HIGH
CVE-2016-1689
all versions
Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote
6.5MEDIUM
CVE-2016-1688
all versions
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mi
6.5MEDIUM
CVE-2016-1687
all versions
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allo
6.5MEDIUM
CVE-2016-1686
all versions
The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chro
6.5MEDIUM
CVE-2016-1685
all versions
core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which all
6.5MEDIUM
CVE-2016-1683
all versions
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote
7.5HIGH
CVE-2016-1682
all versions
The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp
6.1MEDIUM
CVE-2016-1681
all versions
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome befor
8.8HIGH
CVE-2016-1680
all versions
Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote
8.8HIGH
CVE-2016-1679
all versions
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does no
8.8HIGH
CVE-2016-1678
all versions
objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimiza
8.8HIGH
CVE-2016-1677
all versions
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows re
6.5MEDIUM
CVE-2016-1676
all versions
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prot
8.8HIGH
CVE-2016-1675
all versions
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mi
8.8HIGH
CVE-2016-1674
all versions
The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspeci
8.8HIGH
CVE-2016-1673
all versions
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vect
8.8HIGH
CVE-2016-1672
all versions
The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome be
8.8HIGH
CVE-2016-2807
all versions
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firef
8.8HIGH
CVE-2016-2806
all versions
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow r
8.8HIGH
CVE-2016-1659
all versions
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly
9.8CRITICAL
CVE-2016-1656
all versions
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname re
7.5HIGH
CVE-2016-1655
all versions
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows
8.8HIGH
CVE-2016-1654
all versions
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote at
6.5MEDIUM
CVE-2016-1653
all versions
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remo
8.8HIGH
CVE-2016-1652
all versions
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc i
6.1MEDIUM
CVE-2016-1651
all versions
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc42
8.1HIGH
CVE-2016-2802
all versions
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
8.8HIGH
CVE-2016-2801
all versions
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before
8.8HIGH
CVE-2016-2800
all versions
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E
8.8HIGH
CVE-2016-2799
all versions
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before
8.8HIGH
CVE-2016-2798
all versions
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox
8.8HIGH
CVE-2016-2797
all versions
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firef
8.8HIGH
CVE-2016-2796
all versions
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firef
8.8HIGH
CVE-2016-2795
all versions
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR
8.8HIGH
CVE-2016-2794
all versions
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 an
8.8HIGH
CVE-2016-2793
all versions
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote
8.8HIGH
CVE-2016-2792
all versions
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E
8.8HIGH
CVE-2016-2791
all versions
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x
8.8HIGH
CVE-2016-2790
all versions
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 3
8.8HIGH
CVE-2016-1977
all versions
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Fire
8.8HIGH
CVE-2016-1974
all versions
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that
8.8HIGH
CVE-2016-1964
all versions
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allo
8.8HIGH
CVE-2016-1961
all versions
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0
8.8HIGH
CVE-2016-1960
all versions
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x b
8.8HIGH
CVE-2015-1241
all versions
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events
CVE-2013-4480
all versions
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which
CVE-2011-0609
all versions
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and
7.8HIGH
CVE-2010-4180
all versions
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent
CVE-2010-2941
all versions
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, wh
9.8CRITICAL
CVE-2010-1297
all versions
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x bef
7.8HIGH
CVE-2010-1866
all versions
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to
9.8CRITICAL
CVE-2010-0629
all versions
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remo
6.5MEDIUM
CVE-2009-3953
all versions
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 al
8.8HIGH
CVE-2010-0013
all versions
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote a
7.5HIGH
CVE-2009-4324
all versions
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8
7.8HIGH
CVE-2009-3231
all versions
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous bind
CVE-2009-2416
all versions
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-de
6.5MEDIUM
CVE-2009-2408
all versions
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.
5.9MEDIUM
CVE-2009-0949
all versions
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, w
7.5HIGH
CVE-2009-1961
all versions
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 bef
4.7MEDIUM
CVE-2009-0749
all versions
Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allow
7.8HIGH
CVE-2009-0040
all versions
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows
CVE-2008-6123
all versions
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client a
CVE-2008-4989
all versions
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in
5.9MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin