Known vulnerabilities in SUSE Linux Enterprise High Availability 15-SP4

Vendor: SUSE
Version: 15-SP4
Software CPE: cpe:2.3:o:suse:suse_linux_enterprise_high_availability:*:*:*:*:*:*:*:*
Total vulnerabilities: 317
Public exploits: 18
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Linux Enterprise High Availability version 15-SP4 SUSE Linux Enterprise High Availability 15-SP4 is affected by 317 vulnerabilities: 13 high, 50 medium, 254 low Critical High Medium Low

Vulnerabilities (317)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU72334 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-25725
CWE-444 Medium
No
No
- 16.02.2023 SB2023021659
SB2023021662
SB2023021663
and 22 more
#VU72328 - Use After Free
CVE-2022-4382
CWE-416 Low
No
No
- 16.02.2023 SB2023021640
SB2023021641
SB2023021642
and 22 more
#VU72098 - Use After Free
CVE-2023-0590
CWE-416 Low
No
No
- 09.02.2023 SB2023020962
SB2023020963
SB2023020964
and 80 more
#VU72084 - Incorrect Regular Expression
CVE-2023-22799
CWE-185 Medium
No
No
- 09.02.2023 SB2023020945
SB2023020951
SB2023112747
and 4 more
#VU71978 - Resource exhaustion
CVE-2022-44572
CWE-400 Medium
No
No
- 07.02.2023 SB2023020708
SB2023020711
SB2023030241
and 10 more
#VU71977 - Resource exhaustion
CVE-2022-44571
CWE-400 Medium
No
No
- 07.02.2023 SB2023020708
SB2023020711
SB2023030241
and 11 more
#VU71974 - Resource exhaustion
CVE-2022-44570
CWE-400 Medium
No
No
- 07.02.2023 SB2023020708
SB2023020711
SB2023030241
and 11 more
#VU71486 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2021-20251
CWE-362 Low
No
No
- 24.01.2023 SB2023012451
SB2023012452
SB2023012453
and 13 more
#VU71482 - Use After Free
CVE-2023-0266
CWE-416 High
No
Exploited
- 24.01.2023 SB2023012447
SB2023012450
SB2023012651
and 88 more
#VU71479 - NULL Pointer Dereference
CVE-2022-47929
CWE-476 Medium
No
No
- 24.01.2023 SB2023012444
SB2023012450
SB2023012651
and 62 more
#VU71478 - Type confusion
CVE-2023-23454
CWE-843 Low
No
No
- 24.01.2023 SB2023012443
SB2023012450
SB2023012626
and 91 more
#VU71477 - Type confusion
CVE-2023-23455
CWE-843 Low
No
No
- 24.01.2023 SB2023012442
SB2023012450
SB2023012651
and 86 more
#VU71308 - Improper input validation
CVE-2023-22792
CWE-20 Medium
No
No
- 18.01.2023 SB2023011833
SB2023021735
SB2023021739
and 4 more
#VU71307 - Improper input validation
CVE-2023-22795
CWE-20 Medium
No
No
- 18.01.2023 SB2023011833
SB2023021735
SB2023021739
and 5 more
#VU71303 - Improper input validation
CVE-2023-22796
CWE-20 Medium
No
No
- 18.01.2023 SB2023011833
SB2023020662
SB2023030334
and 7 more
#VU71173 - Integer overflow
CVE-2023-0179
CWE-190 Low
Public exploit available
No
- 16.01.2023 SB2023011603
SB2023012450
SB2023021001
and 49 more
#VU71138 - NULL Pointer Dereference
CVE-2023-0122
CWE-476 Medium
No
No
- 12.01.2023 SB2023011235
SB2023021642
SB2023022342
and 5 more
#VU65825 - Permissions, Privileges, and Access Controls
CVE-2022-32744
CWE-264 Low
No
No
- 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 20 more
#VU65820 - Permissions, Privileges, and Access Controls
CVE-2022-2031
CWE-264 Medium
No
No
- 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 15 more
#VU53098 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2020-24588
CWE-451 Low
No
No
- 11.05.2021 SB2021051118
SB2021051227
SB2021051708
and 55 more


Showing elements 1 - 20 out of 317