VendorsSUSEsuse_linux_enterprise_server15
Vulnerabilities

SUSE Linux Enterprise Server 11.0 Service Pack 3 for VMware 15

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2021-25315
salt-api unauthenticated remote code execution
Published 2021-03-03 · Modified
9.8EPSS 0.023
CVE-2023-22643
libzypp-plugin-appdata: potential arbitrary code execution via shell injection due to `os.system` calls
Published 2023-02-07 · Modified
7.8EPSS 0.024
CVE-2019-3691
Local privilege escalation from user munge to root
Published 2020-01-23 · Modified
7.8EPSS 0.005
CVE-2019-18898
trousers: Local privilege escalation from tss to root
Published 2020-01-23 · Modified
7.8EPSS 0.005
CVE-2022-21944
watchman: chown in watchman@.socket unit allows symlink attack
Published 2022-01-26 · Modified
7.8EPSS 0.003
CVE-2018-12122
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.
Published 2018-11-28 · Modified
7.5EPSS 0.413
CVE-2018-12116
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.
Published 2018-11-28 · Modified
7.5EPSS 0.046
CVE-2018-12476
obs-service-extract_file's outfilename parameter allows to write files outside of package directory
Published 2020-01-27 · Modified
7.5EPSS 0.010
CVE-2019-3688
squid: /usr/sbin/pinger packaged with wrong permission
Published 2019-10-07 · Modified
7.1EPSS 0.003
CVE-2020-15707
GRUB2 contained integer overflows when handling the initrd command, leading to a heap-based buffer overflow.
Published 2020-07-29 · Modified
6.4EPSS 0.016
CVE-2020-15705
GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shim
Published 2020-07-29 · Modified
6.4EPSS 0.014
CVE-2020-15706
GRUB2 contains a race condition leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing.
Published 2020-07-29 · Modified
6.4EPSS 0.010
CVE-2018-20105
yast2-rmt exposes CA private key passhrase in log-file
Published 2020-01-27 · Modified
5.5EPSS 0.004
CVE-2019-18900
libzypp stores cookies world readable
Published 2020-01-24 · Modified
4.0EPSS 0.003