Known vulnerabilities in SUSE Linux Enterprise Server 12-SP4 - page 6

Vendor: SUSE
Version: 12-SP4
Software CPE: cpe:2.3:o:suse:suse_linux_enterprise_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 218
Public exploits: 13
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Linux Enterprise Server version 12-SP4 SUSE Linux Enterprise Server 12-SP4 is affected by 218 vulnerabilities: 15 high, 70 medium, 133 low Critical High Medium Low

Vulnerabilities (218)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU67166 - Server-Side Request Forgery (SSRF)
CVE-2022-35949
CWE-918 Medium
No
No
- 11.09.2022 SB2022091109
SB2022091110
SB2022091217
and 4 more
#VU67164 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-35948
CWE-93 Medium
No
No
- 11.09.2022 SB2022091109
SB2022091110
SB2022091217
and 4 more
#VU67163 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-31150
CWE-93 Medium
No
No
- 11.09.2022 SB2022091108
SB2022091110
SB2022091217
and 2 more
#VU66698 - Exposure of sensitive information to an unauthorized actor
CVE-2022-29244
CWE-200 Medium
No
No
- 22.08.2022 SB2022082252
SB2022082253
SB2022091110
and 15 more
#VU66591 - Out-of-bounds read
CVE-2022-1462
CWE-125 Low
No
No
- 17.08.2022 SB2022081737
SB2022081739
SB2022081740
and 49 more
#VU66590 - Out-of-bounds write
CVE-2021-33656
CWE-787 Low
No
No
- 17.08.2022 SB2022081736
SB2022081739
SB2022081740
and 48 more
#VU66550 - Resource Management Errors
CVE-2022-36879
CWE-399 Low
No
No
- 16.08.2022 SB2022081643
SB2022081647
SB2022082923
and 47 more
#VU66476 - Improper input validation
CVE-2022-36946
CWE-20 Medium
Public exploit available
No
- 13.08.2022 SB2022081305
SB2022081647
SB2022081739
and 73 more
#VU65833 - Out-of-bounds write
CVE-2021-33655
CWE-787 Low
No
No
- 27.07.2022 SB2022072725
SB2022072814
SB2022081739
and 77 more
#VU65824 - Missing release of memory after effective lifetime
CVE-2022-32742
CWE-401 Low
No
No
- 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 36 more
#VU65771 - Information Exposure Through Timing Discrepancy
CVE-2020-25657
CWE-208 Medium
No
No
- 26.07.2022 SB2021011288
SB2022072601
SB2022072602
and 7 more
#VU64922 - Missing Encryption of Sensitive Data
CVE-2022-2097
CWE-311 Low
No
No
- 05.07.2022 SB2022070509
SB2022070522
SB2022070531
and 112 more
#VU63323 - Memory corruption
CVE-2021-4157
CWE-119 High
No
No
- 17.05.2022 SB2022051833
SB2022062928
SB2022062931
and 27 more
#VU61565 - Exposure of resource to wrong sphere
CVE-2021-26341
CWE-668 Low
No
No
- 23.03.2022 SB2022032308
SB2022071346
SB2022071602
and 32 more
#VU54520 - Improper input validation
CVE-2020-14343
CWE-20 High
Public exploit available
No
- 04.07.2021 SB2021070403
SB2021070404
SB2022042259
and 17 more
#VU54455 - Protection Mechanism Failure
CVE-2020-26541
CWE-693 Low
No
No
- 30.06.2021 SB2020100224
SB2021063015
SB2021063016
and 26 more
#VU26356 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-10109
CWE-444 Medium
No
No
- 24.03.2020 SB2020031234
SB2020032419
SB2020043028
and 8 more
#VU25823 - Improper input validation
CVE-2020-1747
CWE-20 High
No
No
- 09.03.2020 SB2020030903
SB2020041201
SB2020051129
and 21 more
#VU25721 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-8130
CWE-78 High
No
No
- 02.03.2020 SB2020030203
SB2020033103
SB2020052720
and 5 more
#VU28418 - Use After Free
CVE-2019-19377
CWE-416 Low
No
No
- 29.11.2019 SB2019112914
SB2022061630
SB2022061631
and 14 more


Showing elements 101 - 120 out of 218