Suse Linux Enterprise Server

Vendor:

First CVE: Jul 9, 2008 · Active for 18 years

91
Total CVEs
More Total CVEs than 99% of tracked products
9.1
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Suse Linux Enterprise Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 9, 2008
18 years ago
Most Recent CVE
Feb 4, 2020
2,366 days ago

CVE Severity & Scoring

Suse Linux Enterprise Server91 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local24 (26.4%)
Network15 (16.5%)
Unknown37 (40.7%)
Physical14 (15.4%)
Adjacent Network1 (1.1%)
Attack Complexity
Low51 (56.0%)
High3 (3.3%)
Unknown37 (40.7%)
User Interaction
None46 (50.5%)
Unknown37 (40.7%)
Required8 (8.8%)
Privileges Required
Low20 (22.0%)
High0 (0.0%)
None34 (37.4%)
Unknown37 (40.7%)

Top CVEs

Signals from CVEs in this product scope (91 CVEs).

91 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on
Feb 24, 201510.089NOYES
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear
Oct 15, 20143.478NOYES
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or
Jul 3, 20167.847NOYES
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code exe
Jun 19, 20177.837NOYES
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local user
Apr 27, 20167.836NOYES
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap me
Apr 27, 20168.435NOYES
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotsp
Jan 21, 201510.035NONO
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause
Jul 6, 201510.031NONO
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related
Jan 21, 20159.331NONO
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory con
Jun 27, 20167.830NOYES

Exploit Exposure

Signals from CVEs in this product scope (91 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
14.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (91 CVEs).

Media Mentions

Signals from CVEs in this product scope (91 CVEs).

Top CNAs Publishing CVEs For Suse Linux Enterprise Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.0706.73.8%011
12110.087.6%01
11.0335.75.1%09
11177.43.4%01
10.056.02.5%00
1014.90.4%00