Known vulnerabilities in SUSE Linux Enterprise High Performance Computing 12 SP4 - page 21

Vendor: SUSE
Version: SP4
Software CPE: cpe:2.3:o:suse:suse_linux_enterprise_high_performance_computing_12:*:*:*:*:*:*:*:*
Total vulnerabilities: 442
Public exploits: 25
Known exploited (KEV): 9
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Linux Enterprise High Performance Computing 12 version SP4 SUSE Linux Enterprise High Performance Computing 12 SP4 is affected by 442 vulnerabilities: 4 critical, 68 high, 193 medium, 177 low Critical High Medium Low

Vulnerabilities (442)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73681 - Memory corruption
CVE-2023-28177
CWE-119 High
No
No
- 14.03.2023 SB2023031479
SB2023031502
SB2023031601
and 6 more
#VU73675 - Memory corruption
CVE-2023-28176
CWE-119 High
No
No
- 14.03.2023 SB2023031479
SB2023031501
SB2023031502
and 37 more
#VU73671 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2023-28164
CWE-451 Medium
No
No
- 14.03.2023 SB2023031479
SB2023031501
SB2023031502
and 38 more
#VU73214 - Out-of-bounds write
CVE-2021-37501
CWE-787 Medium
No
No
- 09.03.2023 SB2023030944
SB2023030948
SB2023031657
and 6 more
#VU73108 - Covert Timing Channel
CVE-2020-25658
CWE-385 Low
No
No
- 07.03.2023 SB2020111232
SB2023030749
SB2022111045
and 7 more
#VU72618 - Improper input validation
CVE-2023-24329
CWE-20 Medium
No
No
- 28.02.2023 SB2023022819
SB2023022822
SB2023030832
and 158 more
#VU72575 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48339
CWE-78 High
No
No
- 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 50 more
#VU72573 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48337
CWE-78 High
No
No
- 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 42 more
#VU72404 - Incorrect Regular Expression
CVE-2023-24807
CWE-185 Medium
No
No
- 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 34 more
#VU72403 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-23936
CWE-113 Medium
No
No
- 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 35 more
#VU72400 - Permissions, Privileges, and Access Controls
CVE-2023-23920
CWE-264 Low
No
No
- 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 55 more
#VU72399 - Resource Management Errors
CVE-2023-23919
CWE-399 Medium
No
No
- 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 33 more
#VU72398 - Permissions, Privileges, and Access Controls
CVE-2023-23918
CWE-264 Medium
No
No
- 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 48 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
- 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71642 - Incorrect Regular Expression
CVE-2022-42969
CWE-185 Medium
No
No
- 30.01.2023 SB2023013033
SB2023013037
SB2023021338
and 11 more
#VU71137 - Incorrect Regular Expression
CVE-2022-40899
CWE-185 Medium
No
No
- 12.01.2023 SB2023011234
SB2023011239
SB2023011240
and 26 more
#VU70433 - Stack-based buffer overflow
CVE-2022-46340
CWE-121 Low
No
No
- 20.12.2022 SB2022122002
SB2022122003
SB2022122004
and 47 more
#VU62036 - Unchecked Return Value
CVE-2022-23806
CWE-252 Medium
No
No
- 10.04.2022 SB2022041002
SB2022041003
SB2022060126
and 46 more
#VU57579 - Memory corruption
CVE-2021-38297
CWE-119 High
Public exploit available
No
- 21.10.2021 SB2021102121
SB2021122801
SB2021102022
and 23 more
#VU86 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2015-4000
CWE-300 Medium
Public exploit available
No
- 04.07.2016 SB2015071003
SB2015070202
SB2015072201
and 36 more


Showing elements 401 - 420 out of 442