← Back

Suse Linux Enterprise Server

suse_linux_enterprise_server

Vendor: Suse • 129 CVEs

CVEs (129)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
8Canonical
DebianGnu+5 more
15Active Iq Unified Manager
Debian LinuxEnterprise Linux+12 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream),...Show more
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.Show less
7Canonical
DebianGnu+4 more
14Debian Linux
Enterprise LinuxEnterprise Linux Atomic Host+11 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitra...Show more
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.Show less
7Canonical
DebianGnu+4 more
14Debian Linux
Enterprise LinuxEnterprise Linux Atomic Host+11 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.Show less
5Debian
FedoraprojectGoogle+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5Debian
FedoraprojectGoogle+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5Debian
FedoraprojectGoogle+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5Debian
FedoraprojectGoogle+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5Debian
FedoraprojectGoogle+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5Debian
FedoraprojectGoogle+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5Debian
FedoraprojectGoogle+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Nextcloud
OpensuseSuse
3Backports
Nextcloud ServerSuse Linux Enterprise Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
3Opensuse
SuseYast2 Rmt Project
3Leap
Suse Linux Enterprise ServerYast2 Rmt
Nov 21, 2024
Jan 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affe...Show more
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.Show less
3Debian
PhpmyadminSuse
3Debian Linux
PhpmyadminSuse Linux Enterprise Server
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker mus...Show more
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.Show less
1Suse
1Suse Linux Enterprise Server
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 pe...Show more
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binaryShow less
2Dcraw Project
Suse
3Dcraw
Suse Linux Enterprise DesktopSuse Linux Enterprise Server
Nov 21, 2024
Nov 29, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecif...Show more
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.Show less
2Nodejs
Suse
4Node.js
Suse Enterprise StorageSuse Linux Enterprise Server+1 more
Dec 13, 2024
Nov 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connection...Show more
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.Show less
2Nodejs
Suse
4Node.js
Suse Enterprise StorageSuse Linux Enterprise Server+1 more
Nov 21, 2024
Nov 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provi...Show more
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.Show less
3Libwpd Project
RedhatSuse
3Enterprise Linux
LibwpdSuse Linux Enterprise Server
Nov 21, 2024
Nov 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.
4Debian
LighttpdOpensuse+1 more
5Backports Sle
Debian LinuxLeap+2 more
Nov 21, 2024
Nov 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration w...Show more
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.Show less
4Canonical
LinuxcontainersOpensuse+1 more
6Caas Platform
LeapLxc+3 more
Jun 17, 2026
Aug 10, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise...Show more
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.Show less