Known vulnerabilities in SUSE Package Hub for SUSE Linux Enterprise - page 2

Vendor: SUSE
Software CPE: cpe:2.3:a:suse:suse_package_hub_for_suse_linux_enterprise:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 204
Public exploits: 20
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SUSE Package Hub for SUSE Linux Enterprise SUSE Package Hub for SUSE Linux Enterprise is affected by 204 known vulnerabilities: 2 critical, 83 high, 57 medium, 62 low Critical High Medium Low

Vulnerabilities (204)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU26497 - Heap-based Buffer Overflow
CVE-2020-6452
CWE-122 High
No
No
- 01.04.2020 SB2020040102
SB2020040141
SB2020040740
and 22 more
#VU26496 - Use After Free
CVE-2020-6451
CWE-416 High
No
No
- 01.04.2020 SB2020040102
SB2020040141
SB2020040740
and 22 more
#VU26495 - Use After Free
CVE-2020-6450
CWE-416 High
No
No
- 01.04.2020 SB2020040102
SB2020040141
SB2020040740
and 22 more
#VU26290 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-10803
CWE-79 Low
No
No
- 21.03.2020 SB2020032102
SB2020033001
SB2020033003
and 8 more
#VU26289 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-10802
CWE-89 Low
No
No
- 21.03.2020 SB2020032102
SB2020033001
SB2020033003
and 8 more
#VU26288 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-10804
CWE-89 Low
No
No
- 21.03.2020 SB2020032102
SB2020033001
SB2020033003
and 8 more
#VU26205 - Improper input validation
CVE-2020-6426
CWE-20 High
No
No
- 18.03.2020 SB2020031822
SB2020031909
SB2020032201
and 23 more
#VU26204 - Permissions, Privileges, and Access Controls
CVE-2020-6425
CWE-264 Medium
No
No
- 18.03.2020 SB2020031822
SB2020031909
SB2020032201
and 23 more
#VU26200 - Use After Free
CVE-2020-6427
CWE-416 High
No
No
- 18.03.2020 SB2020031822
SB2020031909
SB2020032201
and 23 more
#VU26201 - Use After Free
CVE-2020-6428
CWE-416 High
No
No
- 18.03.2020 SB2020031822
SB2020031909
SB2020032201
and 23 more
#VU26199 - Use After Free
CVE-2020-6424
CWE-416 High
No
No
- 18.03.2020 SB2020031822
SB2020031909
SB2020032201
and 23 more
#VU26198 - Use After Free
CVE-2020-6422
CWE-416 High
No
No
- 18.03.2020 SB2020031822
SB2020031909
SB2020032201
and 23 more
#VU25856 - Out-of-bounds read
CVE-2019-20503
CWE-125 Medium
No
No
- 10.03.2020 SB2020031005
SB2020031006
SB2020031019
and 54 more
#VU25543 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-8813
CWE-78 High
Available
No
- 24.02.2020 SB2020022410
SB2020050102
SB2020031332
and 8 more
#VU24394 - Improper input validation
CVE-2020-7237
CWE-20 High
No
No
- 20.01.2020 SB2020011616
SB2020031923
SB2020031331
and 9 more
#VU24356 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-7106
CWE-79 Low
No
No
- 16.01.2020 SB2020011616
SB2020031923
SB2020051147
and 11 more
#VU23620 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-17357
CWE-89 Medium
No
No
- 16.12.2019 SB2019121614
SB2020012104
SB2020031923
and 7 more
#VU23619 - Deserialization of Untrusted Data
CVE-2019-17358
CWE-502 High
No
No
- 16.12.2019 SB2019121614
SB2020012104
SB2020031923
and 8 more
#VU21303 - Improper Access Control
CVE-2019-16723
CWE-284 Medium
No
No
- 24.09.2019 SB2019092410
SB2020012104
SB2020031923
and 9 more
#VU36235 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20726
CWE-79 Low
No
No
- 16.01.2019 SB2019011620
SB2020043036
SB2020042875
and 5 more


Showing elements 21 - 40 out of 204