Suse Linux Enterprise Software Development Kit

Vendor:

First CVE: Nov 23, 2013 · Active for 12 years

65
Total CVEs
More Total CVEs than 99% of tracked products
10.8
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Suse Linux Enterprise Software Development Kit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2013
12 years ago
Most Recent CVE
Jan 31, 2020
2,370 days ago

CVE Severity & Scoring

Suse Linux Enterprise Software Development Kit65 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local16 (24.6%)
Network13 (20.0%)
Unknown21 (32.3%)
Physical14 (21.5%)
Adjacent Network1 (1.5%)
Attack Complexity
Low41 (63.1%)
High3 (4.6%)
Unknown21 (32.3%)
User Interaction
None36 (55.4%)
Unknown21 (32.3%)
Required8 (12.3%)
Privileges Required
Low11 (16.9%)
High0 (0.0%)
None33 (50.8%)
Unknown21 (32.3%)

Top CVEs

Signals from CVEs in this product scope (65 CVEs).

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on
Feb 24, 201510.089NOYES
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear
Oct 15, 20143.478NOYES
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or
Jul 3, 20167.847NOYES
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local user
Apr 27, 20167.836NOYES
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap me
Apr 27, 20168.435NOYES
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause
Jul 6, 201510.031NONO
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory con
Jun 27, 20167.830NOYES
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
Sep 20, 20167.529NONO
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7
Jun 3, 20168.129NONO
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application
Jun 13, 20168.828NONO

Exploit Exposure

Signals from CVEs in this product scope (65 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
4.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
18.5% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (65 CVEs).

Media Mentions

Signals from CVEs in this product scope (65 CVEs).

Top CNAs Publishing CVEs For Suse Linux Enterprise Software Development Kit

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.0556.64.0%011
12110.087.6%01
11.0295.55.0%08
1114.61.8%01