Suse Linux Enterprise Server

Vendor:

First CVE: Jul 9, 2008 · Active for 18 years

143
Total CVEs
More Total CVEs than 99% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Suse Linux Enterprise Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 9, 2008
18 years ago
Most Recent CVE
Feb 7, 2023
1,263 days ago

CVE Severity & Scoring

Suse Linux Enterprise Server143 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local46 (32.2%)
Network65 (45.5%)
Unknown32 (22.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low100 (69.9%)
High11 (7.7%)
Unknown32 (22.4%)
User Interaction
None84 (58.7%)
Unknown32 (22.4%)
Required27 (18.9%)
Privileges Required
Low39 (27.3%)
High4 (2.8%)
None68 (47.6%)
Unknown32 (22.4%)

Top CVEs

Signals from CVEs in this product scope (143 CVEs).

143 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to exec
May 5, 20168.498YESYES
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit
Mar 19, 20149.887NOYES
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vec
Mar 19, 20149.884NOYES
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac
Feb 18, 20168.183NOYES
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users
May 7, 20145.578YESYES
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi
May 21, 20153.776NOYES
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown
Feb 16, 20126.864NONO
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creati
Jan 9, 20208.861NOYES
Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey b
Mar 19, 201410.051NONO

Exploit Exposure

Signals from CVEs in this product scope (143 CVEs).

CISA KEV
2 CVEs
1.4% of CVEs· 96th percentile
Metasploit
4 CVEs
2.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
10.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (143 CVEs).

Media Mentions

Signals from CVEs in this product scope (143 CVEs).

Top CNAs Publishing CVEs For Suse Linux Enterprise Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1576.76.4%00
12467.716.2%15
11.074.53.1%00
11757.510.1%17
10237.02.7%03