Known vulnerabilities in SUSE Linux Enterprise Server 15 SP6 LTSS - page 32

Vendor: SUSE
Version: LTSS
Software CPE: cpe:2.3:o:suse:suse_linux_enterprise_server_15_sp6:*:*:*:*:*:*:*:*
Total vulnerabilities: 1484
Public exploits: 27
Known exploited (KEV): 11
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Linux Enterprise Server 15 SP6 version LTSS SUSE Linux Enterprise Server 15 SP6 LTSS is affected by 1484 vulnerabilities: 9 critical, 229 high, 518 medium, 728 low Critical High Medium Low

Vulnerabilities (1484)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131139 - Out-of-bounds write
CVE-2026-2291
CWE-787 Medium
No
No
- 12.05.2026 SB2026051245
SB20260513103
SB20260513104
and 13 more
#VU128398 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-41205
CWE-22 Medium
No
No
- 28.04.2026 SB20260428216
SB2026050603
SB2026051399
and 2 more
#VU126765 - Improper input validation
CVE-2026-22007
CWE-20 Low
No
No
- 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU126523 - Integer overflow
CVE-2026-40244
CWE-190 High
No
No
- 20.04.2026 SB2026042063
SB2026050308
SB2026050309
and 3 more
#VU126522 - Integer overflow
CVE-2026-40250
CWE-190 High
No
No
- 20.04.2026 SB2026042063
SB2026050308
SB2026050309
and 3 more
#VU125895 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-40176
CWE-78 High
No
No
- 14.04.2026 SB2026041445
SB2026041481
SB2026041482
and 8 more
#VU125894 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-40261
CWE-78 High
No
No
- 14.04.2026 SB2026041445
SB2026041481
SB2026041482
and 8 more
#VU125866 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-2332
CWE-444 Medium
No
No
- 14.04.2026 SB2026041433
SB2026050517
SB20260507308
and 9 more
#VU125816 - Sensitive Information in Resource Not Removed Before Reuse
CVE-2026-5795
CWE-226 High
No
No
- 11.04.2026 SB2026041112
SB20260507308
SB2026052932
and 3 more
#VU125777 - Incorrect Authorization
CVE-2026-28808
CWE-863 High
No
No
- 10.04.2026 SB2026041031
SB2026041046
SB2026041047
and 5 more
#VU125775 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-23941
CWE-444 High
No
No
- 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125774 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-23942
CWE-22 Low
No
No
- 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125773 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-23943
CWE-409 Medium
No
No
- 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 5 more
#VU125772 - Relative Path Traversal
CVE-2026-21620
CWE-23 Low
No
No
- 10.04.2026 SB2026041021
SB2026041023
SB2026041024
and 6 more
#VU125602 - Use After Free
CVE-2026-34757
CWE-416 Low
No
No
- 09.04.2026 SB2026040960
SB2026042128
SB20260422224
and 9 more
#VU124482 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-28753
CWE-93 Medium
No
No
- 25.03.2026 SB2026032585
SB20260325200
SB2026041117
and 3 more
#VU124480 - Integer overflow
CVE-2026-27784
CWE-190 High
No
No
- 25.03.2026 SB2026032585
SB20260325200
SB2026040801
and 16 more
#VU124478 - Heap-based Buffer Overflow
CVE-2026-27654
CWE-122 Medium
Public exploit available
No
- 25.03.2026 SB2026032585
SB20260325200
SB2026033174
and 16 more
#VU122335 - Acceptance of Extraneous Untrusted Data With Trusted Data
CVE-2026-1642
CWE-349 Medium
No
No
- 05.02.2026 SB2026020501
SB2026020505
SB2026020511
and 21 more
#VU19180 - Improper input validation
CVE-2017-12652
CWE-20 Low
No
No
- 15.07.2019 SB2019071033
SB2020020613
SB2020093077
and 16 more


Showing elements 621 - 640 out of 1484