Suse Linux Enterprise Debuginfo
Vendor:
First CVE: Nov 23, 2013 · Active for 12 years
24
Total CVEs
More Total CVEs than 96% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 13% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Suse Linux Enterprise Debuginfo over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2013
12 years ago
Most Recent CVE
Jan 31, 2020
2,370 days ago
CVE Severity & Scoring
Suse Linux Enterprise Debuginfo24 CVEs
8%
75%
17%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local10 (41.7%)
Network1 (4.2%)
Unknown1 (4.2%)
Physical11 (45.8%)
Adjacent Network1 (4.2%)
Attack Complexity
Low23 (95.8%)
High0 (0.0%)
Unknown1 (4.2%)
User Interaction
None23 (95.8%)
Unknown1 (4.2%)
Required0 (0.0%)
Privileges Required
Low6 (25.0%)
High1 (4.2%)
None16 (66.7%)
Unknown1 (4.2%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3134HIGH The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap me | Apr 27, 2016 | 8.4 | 35 | NO | YES |
CVE-2016-1583HIGH The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory con | Jun 27, 2016 | 7.8 | 30 | NO | YES |
CVE-2016-3140MEDIUM The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointe | May 2, 2016 | 4.6 | 28 | NO | YES |
CVE-2016-2184MEDIUM The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of | Apr 27, 2016 | 4.6 | 28 | NO | YES |
CVE-2016-2188MEDIUM The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer deref | May 2, 2016 | 4.6 | 26 | NO | YES |
CVE-2016-3139MEDIUM The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer derefe | Apr 27, 2016 | 4.6 | 26 | NO | YES |
CVE-2016-4913HIGH The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local use | May 23, 2016 | 7.8 | 25 | NO | NO |
CVE-2016-4485HIGH The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information | May 23, 2016 | 7.5 | 25 | NO | NO |
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitiv | May 23, 2016 | 3.3 | 24 | NO | YES |
CVE-2016-4482MEDIUM The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive | May 23, 2016 | 6.2 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
33.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Suse Linux Enterprise Debuginfo
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.0 | 17 | 5.3 | 1.1% | 0 | 7 |
| 11 | 7 | 5.5 | 1.6% | 0 | 1 |