Known vulnerabilities in SUSE Linux Enterprise Module for Web Scripting 15-SP3 - page 3

Vendor: SUSE
Version: 15-SP3
Software CPE: cpe:2.3:o:suse:suse_linux_enterprise_module_for_web_scripting:*:*:*:*:*:*:*:*
Total vulnerabilities: 66
Public exploits: 7
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Linux Enterprise Module for Web Scripting version 15-SP3 SUSE Linux Enterprise Module for Web Scripting 15-SP3 is affected by 66 vulnerabilities: 10 high, 49 medium, 7 low Critical High Medium Low

Vulnerabilities (66)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU61257 - UNIX Symbolic Link (Symlink) Following
CVE-2021-39135
CWE-61 Low
No
No
- 11.03.2022 SB2021083138
SB2022031104
SB2021120224
and 6 more
#VU61254 - Use After Free
CVE-2021-22940
CWE-416 Medium
No
No
- 11.03.2022 SB2021081615
SB2022031104
SB2022060618
and 23 more
#VU61253 - Improper Certificate Validation
CVE-2021-22939
CWE-295 Medium
No
No
- 11.03.2022 SB2021081614
SB2022031104
SB2022060618
and 25 more
#VU59234 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22960
CWE-444 Medium
No
No
- 05.01.2022 SB2022010523
SB2022010524
SB2022042806
and 40 more
#VU59233 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22959
CWE-444 Medium
No
No
- 05.01.2022 SB2022010523
SB2022010524
SB2022011841
and 43 more
#VU58331 - Improper input validation
CVE-2021-21707
CWE-20 Medium
No
No
- 23.11.2021 SB2021112317
SB2021112318
SB2022011821
and 21 more
#VU58202 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37701
CWE-22 Medium
No
No
- 17.11.2021 SB2021111706
SB2021111710
SB2022031104
and 24 more
#VU57656 - Out-of-bounds write
CVE-2021-21703
CWE-787 Low
No
No
- 26.10.2021 SB2021102621
SB2021102719
SB2022012745
and 20 more
#VU57498 - Improper input validation
CVE-2021-22931
CWE-20 High
No
No
- 19.10.2021 SB2021101945
SB2022020113
SB2022031104
and 28 more
#VU56967 - Improper input validation
CVE-2021-3672
CWE-20 Medium
No
No
- 30.09.2021 SB2021093017
SB2021110508
SB2022031104
and 39 more
#VU56634 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-41079
CWE-835 Medium
No
No
- 15.09.2021 SB2021091527
SB2021100721
SB2021101512
and 16 more
#VU55560 - Use After Free
CVE-2021-22930
CWE-416 High
No
No
- 03.08.2021 SB2021080320
SB2021080324
SB2021080325
and 35 more
#VU55423 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-33037
CWE-444 Medium
No
No
- 29.07.2021 SB2021072907
SB2021080807
SB2021080808
and 30 more
#VU55417 - Improper Authentication
CVE-2021-30640
CWE-287 Medium
No
No
- 29.07.2021 SB2021072901
SB2021072902
SB2021081231
and 14 more
#VU54624 - Out-of-bounds read
CVE-2021-22918
CWE-125 Medium
No
No
- 08.07.2021 SB2021070819
SB2021072009
SB2021081123
and 40 more
#VU54566 - Stack-based buffer overflow
CVE-2021-21704
CWE-121 High
No
No
- 06.07.2021 SB2021070611
SB2021070612
SB2021070613
and 17 more
#VU54565 - Server-Side Request Forgery (SSRF)
CVE-2021-21705
CWE-918 Medium
No
No
- 06.07.2021 SB2021070611
SB2021070612
SB2021070613
and 21 more
#VU52909 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7774
CWE-94 Medium
No
No
- 06.05.2021 SB2020111735
SB2021050615
SB2021092814
and 24 more
#VU52194 - Incorrect Regular Expression
CVE-2021-27290
CWE-185 Medium
No
No
- 12.03.2021 SB2021041364
SB2021070819
SB2021101939
and 32 more
#VU49907 - UNIX Symbolic Link (Symlink) Following
CVE-2020-36193
CWE-61 High
Public exploit available
Exploited
- 18.01.2021 SB2021012112
SB2021012113
SB2021012410
and 20 more


Showing elements 41 - 60 out of 66