Linux Enterprise

Vendor:

First CVE: Nov 13, 2008 · Active for 17 years

139
Total CVEs
More Total CVEs than 99% of tracked products
9.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Linux Enterprise over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 13, 2008
17 years ago
Most Recent CVE
Jan 12, 2024
924 days ago

CVE Severity & Scoring

Linux Enterprise139 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local18 (12.9%)
Network115 (82.7%)
Unknown6 (4.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low119 (85.6%)
High14 (10.1%)
Unknown6 (4.3%)
User Interaction
None34 (24.5%)
Unknown6 (4.3%)
Required99 (71.2%)
Privileges Required
Low14 (10.1%)
High0 (0.0%)
None119 (85.6%)
Unknown6 (4.3%)

Top CVEs

Signals from CVEs in this product scope (139 CVEs).

139 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac
Jun 8, 20107.897YESYES
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code vi
Jan 13, 20108.897YESYES
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remo
Dec 15, 20097.897YESYES
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; a
Mar 15, 20117.895YESYES
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbi
Mar 13, 20168.853NOYES
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly tri
May 7, 20109.843NOYES
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot
Jan 9, 20107.540NOYES
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of
Jun 9, 20097.538NOYES
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of s
Nov 5, 20109.833NONO
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are
Jul 23, 20196.532NONO

Exploit Exposure

Signals from CVEs in this product scope (139 CVEs).

CISA KEV
4 CVEs
2.9% of CVEs· 96th percentile
Metasploit
4 CVEs
2.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
6.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (139 CVEs).

Media Mentions

Signals from CVEs in this product scope (139 CVEs).

Top CNAs Publishing CVEs For Linux Enterprise

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9-1126.42.2%00
9.027.212.2%01
15.087.21.3%00
12.0747.72.4%01
11.0147.418.1%25
10.0127.738.2%46