← Back to Products

suse_linux_enterprise_desktop

Vendor: suse

8
Total CVEs
3
Critical
2
High
2
Medium
1
Low

Recent CVEs

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page....

Affected versions: 12

Published: Mar 23, 2020

8.8

CVSS

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page....

Affected versions: 12

Published: Mar 23, 2020

8.8

CVSS

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page....

Affected versions: 12

Published: Mar 23, 2020

8.8

CVSS

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page....

Affected versions: 12

Published: Mar 23, 2020

8.8

CVSS

Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page....

Affected versions: 12

Published: Mar 23, 2020

6.5

CVSS

Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page....

Affected versions: 12

Published: Mar 23, 2020

8.8

CVSS

Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page....

Affected versions: 12

Published: Mar 23, 2020

8.8

CVSS

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of serv...

Affected versions: 11.0 12.0

Published: Jan 31, 2020

3.5

CVSS

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-...

Affected versions: 12

Published: Nov 29, 2018

6.8

CVSS

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in tha...

Affected versions: 11

Published: Jun 8, 2018

3.5

CVSS

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis....

Affected versions: 12

Published: Jan 4, 2018

5.6

CVSS

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root....

Affected versions: 12.0

Published: Sep 8, 2017

6.9

CVSS

ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is betwee...

Affected versions: 11.0

Published: Aug 9, 2017

5.0

CVSS

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note ...

Affected versions: 12.0

Published: Jun 19, 2017

7.2

CVSS

game-music-emu before 0.6.1 mishandles unspecified integer values....

Affected versions: 12.0

Published: Jun 6, 2017

10.0

CVSS

game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash)....

Affected versions: 12.0

Published: Jun 6, 2017

2.1

CVSS

ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash)....

Affected versions: 12.0

Published: Mar 20, 2017

5.0

CVSS

Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption)....

Affected versions: 12.0

Published: Mar 20, 2017

5.0

CVSS

The png coder in ImageMagick allows remote attackers to cause a denial of service (crash)....

Affected versions: 12.0

Published: Mar 20, 2017

5.0

CVSS

Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption)....

Affected versions: 12.0

Published: Mar 20, 2017

7.5

CVSS

The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact....

Affected versions: 12.0

Published: Mar 20, 2017

7.5

CVSS

Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact....

Affected versions: 12.0

Published: Mar 20, 2017

7.5

CVSS

The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file....

Affected versions: 12.0

Published: Mar 20, 2017

4.3

CVSS

The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file....

Affected versions: 12.0

Published: Mar 20, 2017

4.3

CVSS

The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors....

Affected versions: 12.0

Published: Mar 20, 2017

7.5

CVSS

Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors....

Affected versions: 12.0

Published: Mar 20, 2017

5.0

CVSS

The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."...

Affected versions: 12.0

Published: Mar 20, 2017

7.5

CVSS

The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be re...

Affected versions: 12

Published: Oct 13, 2016

4.9

CVSS

The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted...

Affected versions: 12.0

Published: Sep 20, 2016

4.3

CVSS

The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file....

Affected versions: 12.0

Published: Sep 20, 2016

4.3

CVSS

The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z...

Affected versions: 12.0

Published: Sep 20, 2016

4.3

CVSS

The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file....

Affected versions: 12.0

Published: Sep 20, 2016

5.0

CVSS

The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file....

Affected versions: 12.0

Published: Sep 20, 2016

4.3

CVSS

The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) l...

Affected versions: 12.0

Published: Sep 20, 2016

5.0

CVSS

The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."...

Affected versions: 12.0

Published: Sep 20, 2016

5.0

CVSS

The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of s...

Affected versions: 12.0

Published: Jul 3, 2016

7.8

CVSS

The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vector...

Affected versions: 12.0

Published: Jun 27, 2016

7.8

CVSS

Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly ...

Affected versions: 12.0

Published: Jun 13, 2016

9.3

CVSS

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and ap...

Affected versions: 12.0

Published: Jun 13, 2016

6.8

CVSS

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exec...

Affected versions: 12.0

Published: Jun 13, 2016

6.8

CVSS

Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or poss...

Affected versions: 12.0

Published: May 23, 2016

7.8

CVSS

The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from ker...

Affected versions: 12.0

Published: May 23, 2016

2.1

CVSS

The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from k...

Affected versions: 12.0

Published: May 23, 2016

2.1

CVSS

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from ke...

Affected versions: 12.0

Published: May 23, 2016

2.1

CVSS

Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified oth...

Affected versions: 12

Published: May 2, 2016

4.9

CVSS

The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device ...

Affected versions: 12.0

Published: May 2, 2016

4.9

CVSS

The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and sy...

Affected versions: 12.0

Published: May 2, 2016

4.9

CVSS

The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) vi...

Affected versions: 12.0

Published: May 2, 2016

4.9

CVSS

drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without...

Affected versions: 12.0

Published: May 2, 2016

4.9

CVSS

The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and sy...

Affected versions: 12.0

Published: May 2, 2016

4.9

CVSS