← Back

Suse Linux Enterprise Server

suse_linux_enterprise_server

Vendor: Suse • 129 CVEs

CVEs (129)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Suse
2Suse Linux Enterprise Desktop
Suse Linux Enterprise Server
Nov 21, 2024
Jun 8, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implemen...Show more
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).Show less
1Suse
1Suse Linux Enterprise Server
Nov 21, 2024
Jun 8, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
2Postgresql
Suse
2Postgresql
Suse Linux Enterprise Server
Nov 21, 2024
Mar 1, 2018
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
13Arm
CanonicalDebian+10 more
308Atom C
Atom EAtom X3+305 more
May 28, 2026
Jan 4, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
7Debian
FedoraprojectNtp+4 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 more
May 13, 2026
Aug 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and...Show more
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.Show less
7Canonical
DebianFedoraproject+4 more
20Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+17 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).Show less
4Game Music Emu Project
OpensuseOpensuse Project+1 more
9Game Music Emu
LeapLeap+6 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
4Game Music Emu Project
OpensuseOpensuse Project+1 more
9Game Music Emu
LeapLeap+6 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
4Game Music Emu Project
OpensuseOpensuse Project+1 more
9Game Music Emu
LeapLeap+6 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in game-music-emu before 0.6.1.
1Suse
3Linux Enterprise Desktop
Linux Enterprise ServerSuse Linux Enterprise Server
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as...Show more
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).Show less
4Canonical
ImagemagickOpensuse+1 more
7Imagemagick
LeapLinux Enterprise Server+4 more
May 13, 2026
Mar 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
4Novell
NtpOpensuse+1 more
10Leap
Linux Enterprise DebuginfoLinux Enterprise Desktop+7 more
May 13, 2026
Jan 30, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
4Fedoraproject
LinuxRedhat+1 more
11Enterprise Linux
FedoraLinux Enterprise Debuginfo+8 more
May 6, 2026
Jun 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by...Show more
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.Show less
3Ibm
RedhatSuse
6Java Sdk
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Jun 6, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-...Show more
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.Show less
3Ibm
RedhatSuse
13Enterprise Linux Desktop
Enterprise Linux Hpc Node SupplementaryEnterprise Linux Server+10 more
May 6, 2026
May 24, 2016
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8...Show more
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.Show less
5Canonical
DebianImagemagick+2 more
6Debian Linux
ImagemagickLeap+3 more
Apr 21, 2026
May 5, 2016
N/A· v4
8.4 HIGH· v3
10.0 HIGH· v2
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharact...Show more
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range...Show more
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.Show less
5Canonical
FedoraprojectGnu+2 more
9Fedora
GlibcLinux Enterprise Debuginfo+6 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.Show less