Suse Linux Enterprise Server

Vendor:

First CVE: Jul 17, 2014 · Active for 12 years

15
Total CVEs
More Total CVEs than 64% of tracked products
3.8
Avg CVEs / Year
Bottom 1%
8.0
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Suse Linux Enterprise Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2014
12 years ago
Most Recent CVE
Feb 22, 2020
2,345 days ago

CVE Severity & Scoring

Suse Linux Enterprise Server15 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local2 (13.3%)
Network12 (80.0%)
Unknown1 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High0 (0.0%)
Unknown1 (6.7%)
User Interaction
None11 (73.3%)
Unknown1 (6.7%)
Required3 (20.0%)
Privileges Required
Low1 (6.7%)
High0 (0.0%)
None13 (86.7%)
Unknown1 (6.7%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
Feb 22, 20208.880NOYES
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
Mar 20, 20179.827NONO
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
Mar 20, 20179.826NONO
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
Mar 20, 20179.825NONO
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
Mar 20, 20179.825NONO
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to
Mar 13, 20168.825NONO
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the tem
Aug 9, 20177.521NONO
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
Mar 20, 20177.520NONO
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
Mar 20, 20177.520NONO
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
Mar 20, 20177.520NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.7% of CVEs· 98th percentile
ExploitDB
1 CVE
6.7% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Suse Linux Enterprise Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.0128.03.5%00
11.097.43.7%00