Suse Linux Enterprise Desktop

Vendor:

First CVE: Jul 9, 2008 · Active for 18 years

81
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 72% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Suse Linux Enterprise Desktop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 9, 2008
18 years ago
Most Recent CVE
Sep 19, 2023
1,043 days ago

CVE Severity & Scoring

Suse Linux Enterprise Desktop81 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local17 (21.0%)
Network31 (38.3%)
Unknown33 (40.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low45 (55.6%)
High3 (3.7%)
Unknown33 (40.7%)
User Interaction
None34 (42.0%)
Unknown33 (40.7%)
Required14 (17.3%)
Privileges Required
Low17 (21.0%)
High0 (0.0%)
None31 (38.3%)
Unknown33 (40.7%)

Top CVEs

Signals from CVEs in this product scope (81 CVEs).

81 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit
Mar 19, 20149.887NOYES
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vec
Mar 19, 20149.884NOYES
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users
May 7, 20145.578YESYES
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or caus
Apr 14, 201510.061NOYES
Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey b
Mar 19, 201410.051NONO
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory req
Sep 24, 20107.839NOYES
The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers t
Dec 11, 20139.837NONO
vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destinat
Mar 19, 20149.836NONO
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow re
Dec 11, 20139.836NONO

Exploit Exposure

Signals from CVEs in this product scope (81 CVEs).

CISA KEV
1 CVE
1.2% of CVEs· 97th percentile
Metasploit
2 CVEs
2.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
11.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (81 CVEs).

Media Mentions

Signals from CVEs in this product scope (81 CVEs).

Top CNAs Publishing CVEs For Suse Linux Enterprise Desktop

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1517.80.3%00
12.0179.78.8%01
1298.019.0%01
11.0228.97.8%01
11447.78.1%15
10117.11.9%02