Suse Linux Enterprise Debuginfo

Vendor:

First CVE: Nov 23, 2013 · Active for 12 years

24
Total CVEs
More Total CVEs than 96% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 13% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Suse Linux Enterprise Debuginfo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2013
12 years ago
Most Recent CVE
Jan 31, 2020
2,370 days ago

CVE Severity & Scoring

Suse Linux Enterprise Debuginfo24 CVEs
All CVEs353,173 CVEs
LowMediumHigh
Attack Vector
Local10 (41.7%)
Network1 (4.2%)
Unknown1 (4.2%)
Physical11 (45.8%)
Adjacent Network1 (4.2%)
Attack Complexity
Low23 (95.8%)
High0 (0.0%)
Unknown1 (4.2%)
User Interaction
None23 (95.8%)
Unknown1 (4.2%)
Required0 (0.0%)
Privileges Required
Low6 (25.0%)
High1 (4.2%)
None16 (66.7%)
Unknown1 (4.2%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap me
Apr 27, 20168.435NOYES
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory con
Jun 27, 20167.830NOYES
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointe
May 2, 20164.628NOYES
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of
Apr 27, 20164.628NOYES
The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer deref
May 2, 20164.626NOYES
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer derefe
Apr 27, 20164.626NOYES
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local use
May 23, 20167.825NONO
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information
May 23, 20167.525NONO
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitiv
May 23, 20163.324NOYES
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive
May 23, 20166.223NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
33.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Suse Linux Enterprise Debuginfo

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
11.0175.31.1%07
1175.51.6%01