📦

suse_linux_enterprise_server

Vendor: suse

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 1 Remote Access
Total CVEs 116 Total Indexed
Avg. EPSS 1.44% Exploit Prob.
Latest CVE CVE-2019-3688 Oct 07

Security Vulnerability Index

Page 1 / 12
5.1 CVSS

The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary

EPSS: 0.34%
5.9 CVSS

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).

EPSS: 0.78%
5.4 CVSS

A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.

EPSS: 1.03%
7.8 CVSS

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.

EPSS: 0.38%
7.8 CVSS

A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).

EPSS: 0.54%
4.6 CVSS

Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.

EPSS: 0.49%
4.6 CVSS

net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.

EPSS: 0.47%
7.8 CVSS
CVE-2014-9322
Exploit Found

arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.

EPSS: 1.54%
3.3 CVSS

The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.

EPSS: 0.70%
5.5 CVSS

The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.

EPSS: 0.74%