VendorsSUSElinux_enterprise_server15
Vulnerabilities

SUSE Linux Enterprise Server 15

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2019-3689
nfs-utils: root-owned files stored in insecure /var/lib/nfs directory
Published 2019-09-19 · Modified
10.0EPSS 0.015
CVE-2019-18902
wicked: Use-after-free when receiving invalid DHCP6 client options
Published 2020-03-02 · Modified
9.8EPSS 0.024
CVE-2019-18903
wicked: Use-after-free when receiving invalid DHCP6 IA_PD option
Published 2020-03-02 · Modified
9.8EPSS 0.024
CVE-2019-3681
osc: stores downloaded (supposed) RPM in network-controlled filesystem paths
Published 2020-06-29 · Modified
9.8EPSS 0.014
CVE-2020-8025
outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues
Published 2020-08-07 · Modified
9.3EPSS 0.005
CVE-2019-3695
pcp: Local privilege escalation from user pcp to root
Published 2020-03-03 · Modified
8.4EPSS 0.005
CVE-2019-3696
pcp: Local privilege escalation from user pcp to root through migrate_tempdirs
Published 2020-03-03 · Modified
8.4EPSS 0.005
CVE-2019-18897
Local privilege escalation from user salt to root
Published 2020-03-02 · Modified
8.4EPSS 0.004
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Published 2022-01-28 · Analyzed
7.8KEV1 PoCEPSS 0.943
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Published 2026-04-22 · Analyzed
7.8KEVEPSS 0.034
CVE-2020-8022
User-writeable configuration file /usr/lib/tmpfiles.d/tomcat.conf allows for escalation of priviliges
Published 2020-06-29 · Modified
7.8EPSS 0.009
CVE-2022-27239
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Published 2022-04-27 · Modified
7.8EPSS 0.006
CVE-2021-45082
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
Published 2022-02-18 · Modified
7.8EPSS 0.005
CVE-2020-8023
Local privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2
Published 2020-09-01 · Modified
7.8EPSS 0.004
CVE-2022-31254
rmt-server-pubcloud allows to escalate from user _rmt to root
Published 2023-02-07 · Modified
7.8EPSS 0.002
CVE-2023-29552
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Published 2023-04-25 · Analyzed
7.5KEVEPSS 0.640
CVE-2002-20001
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Published 2021-11-11 · Analyzed
7.5EPSS 0.246
CVE-2018-17962
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
Published 2018-10-09 · Modified
7.5EPSS 0.045
CVE-2019-18904
Migrations requests can cause DoS on rmt
Published 2020-04-03 · Modified
7.5EPSS 0.016
CVE-2020-8027
openldap uses fixed paths in /tmp
Published 2021-02-11 · Modified
7.3EPSS 0.003
CVE-2021-32000
clone-master-clean-up: dangerous file system operations
Published 2021-07-28 · Modified
7.1EPSS 0.003
CVE-2019-9211
There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.
Published 2019-02-27 · Modified
6.5EPSS 0.020
CVE-2019-18905
Deprecated functionality in autoyast2 automatically imports gpg keys without checking them
Published 2020-04-03 · Modified
5.9EPSS 0.007
CVE-2019-18901
mysql-systemd-helper allows setting 640 permissions of arbitrary files
Published 2020-03-02 · Modified
5.5EPSS 0.004
CVE-2023-23005
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
Published 2023-03-01 · Modified
5.5EPSS 0.003
CVE-2022-45154
supportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.sh
Published 2023-02-15 · Modified
5.5EPSS 0.002
CVE-2021-46705
grub2-once uses fixed file name in /var/tmp
Published 2022-03-16 · Modified
5.1EPSS 0.002
CVE-2021-25316
Local DoS of VM live migration due to use of static tmp files in detach_disks.sh in s390-tools
Published 2021-04-14 · Modified
3.3EPSS 0.003
CVE-2020-8013
permissions: chkstat sets unintended setuid/capabilities for mrsh and wodim
Published 2020-03-02 · Modified
2.5EPSS 0.003