threat
engine
.sh
Back
·
··:··
Home
/
Product
/
suse linux enterprise
Product
suse linux enterprise
97 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-23301
all versions
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to
5.5
MEDIUM
CVE-2023-34256
all versions
An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from
5.5
MEDIUM
CVE-2021-4028
all versions
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to
7.8
HIGH
CVE-2021-41819
all versions
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0
7.5
HIGH
CVE-2021-41817
all versions
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed
7.5
HIGH
CVE-2021-4166
all versions
vim is vulnerable to Out-of-bounds Read
7.1
HIGH
CVE-2020-14147
all versions
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permissio
7.7
HIGH
CVE-2018-14523
all versions
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstra
8.8
HIGH
CVE-2018-14522
all versions
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubio
8.8
HIGH
CVE-2016-9959
all versions
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
7.8
HIGH
CVE-2016-9958
all versions
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
7.8
HIGH
CVE-2016-9957
all versions
Stack-based buffer overflow in game-music-emu before 0.6.1.
7.8
HIGH
CVE-2016-8569
all versions
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer
5.5
MEDIUM
CVE-2016-8568
all versions
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bou
5.5
MEDIUM
CVE-2016-7966
all versions
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to t
7.3
HIGH
CVE-2016-7099
all versions
The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7
5.9
MEDIUM
CVE-2016-5325
all versions
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x
6.1
MEDIUM
CVE-2016-5131
all versions
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to ca
8.8
HIGH
CVE-2016-2178
all versions
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time o
5.5
MEDIUM
CVE-2016-1703
all versions
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly
8.8
HIGH
CVE-2016-1702
all versions
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validat
6.5
MEDIUM
CVE-2016-1701
all versions
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript c
8.8
HIGH
CVE-2016-1700
all versions
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation
7.5
HIGH
CVE-2016-1699
all versions
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome be
6.5
MEDIUM
CVE-2016-1698
all versions
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2
6.5
MEDIUM
CVE-2016-1697
all versions
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.27
8.8
HIGH
CVE-2016-1696
all versions
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote atta
8.8
HIGH
CVE-2016-1695
all versions
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly
8.8
HIGH
CVE-2016-1694
all versions
browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which
5.3
MEDIUM
CVE-2016-1693
all versions
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com
5.3
MEDIUM
CVE-2016-1692
all versions
WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading
5.3
MEDIUM
CVE-2016-1691
all versions
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial o
7.5
HIGH
CVE-2016-1690
all versions
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript c
7.5
HIGH
CVE-2016-1689
all versions
Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote
6.5
MEDIUM
CVE-2016-1688
all versions
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mi
6.5
MEDIUM
CVE-2016-1687
all versions
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allo
6.5
MEDIUM
CVE-2016-1686
all versions
The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chro
6.5
MEDIUM
CVE-2016-1685
all versions
core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which all
6.5
MEDIUM
CVE-2016-1683
all versions
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote
7.5
HIGH
CVE-2016-1682
all versions
The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp
6.1
MEDIUM
CVE-2016-1681
all versions
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome befor
8.8
HIGH
CVE-2016-1680
all versions
Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote
8.8
HIGH
CVE-2016-1679
all versions
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does no
8.8
HIGH
CVE-2016-1678
all versions
objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimiza
8.8
HIGH
CVE-2016-1677
all versions
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows re
6.5
MEDIUM
CVE-2016-1676
all versions
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prot
8.8
HIGH
CVE-2016-1675
all versions
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mi
8.8
HIGH
CVE-2016-1674
all versions
The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspeci
8.8
HIGH
CVE-2016-1673
all versions
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vect
8.8
HIGH
CVE-2016-1672
all versions
The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome be
8.8
HIGH
CVE-2016-2807
all versions
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firef
8.8
HIGH
CVE-2016-2806
all versions
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow r
8.8
HIGH
CVE-2016-1659
all versions
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly
9.8
CRITICAL
CVE-2016-1656
all versions
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname re
7.5
HIGH
CVE-2016-1655
all versions
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows
8.8
HIGH
CVE-2016-1654
all versions
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote at
6.5
MEDIUM
CVE-2016-1653
all versions
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remo
8.8
HIGH
CVE-2016-1652
all versions
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc i
6.1
MEDIUM
CVE-2016-1651
all versions
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc42
8.1
HIGH
CVE-2016-2802
all versions
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
8.8
HIGH
CVE-2016-2801
all versions
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before
8.8
HIGH
CVE-2016-2800
all versions
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E
8.8
HIGH
CVE-2016-2799
all versions
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before
8.8
HIGH
CVE-2016-2798
all versions
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox
8.8
HIGH
CVE-2016-2797
all versions
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firef
8.8
HIGH
CVE-2016-2796
all versions
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firef
8.8
HIGH
CVE-2016-2795
all versions
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR
8.8
HIGH
CVE-2016-2794
all versions
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 an
8.8
HIGH
CVE-2016-2793
all versions
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote
8.8
HIGH
CVE-2016-2792
all versions
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E
8.8
HIGH
CVE-2016-2791
all versions
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x
8.8
HIGH
CVE-2016-2790
all versions
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 3
8.8
HIGH
CVE-2016-1977
all versions
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Fire
8.8
HIGH
CVE-2016-1974
all versions
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that
8.8
HIGH
CVE-2016-1964
all versions
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allo
8.8
HIGH
CVE-2016-1961
all versions
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0
8.8
HIGH
CVE-2016-1960
all versions
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x b
8.8
HIGH
CVE-2015-1241
all versions
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events
CVE-2013-4480
all versions
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which
CVE-2011-0609
all versions
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and
7.8
HIGH
CVE-2010-4180
all versions
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent
CVE-2010-2941
all versions
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, wh
9.8
CRITICAL
CVE-2010-1297
all versions
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x bef
7.8
HIGH
CVE-2010-1866
all versions
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to
9.8
CRITICAL
CVE-2010-0629
all versions
Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remo
6.5
MEDIUM
CVE-2009-3953
all versions
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 al
8.8
HIGH
CVE-2010-0013
all versions
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote a
7.5
HIGH
CVE-2009-4324
all versions
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8
7.8
HIGH
CVE-2009-3231
all versions
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous bind
CVE-2009-2416
all versions
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-de
6.5
MEDIUM
CVE-2009-2408
all versions
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.
5.9
MEDIUM
CVE-2009-0949
all versions
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, w
7.5
HIGH
CVE-2009-1961
all versions
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 bef
4.7
MEDIUM
CVE-2009-0749
all versions
Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allow
7.8
HIGH
CVE-2009-0040
all versions
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows
CVE-2008-6123
all versions
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client a
CVE-2008-4989
all versions
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in
5.9
MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin