CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

suse

linux_enterprise

9 known vulnerabilities · sorted by CVSS score

CVE-2018-14523
HIGH8.8

An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.

aubio / aubio+3
Network
Published Jul 23, 2018
CVE-2018-14522
HIGH8.8

An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.

aubio / aubio+3
Network
Published Jul 23, 2018
CVE-2021-4028
HIGH7.8

A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.

linux / linux_kernel+3
Local
Published Aug 24, 2022
CVE-2020-14147
HIGH7.7

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.

redislabs / redis+7
Network
Published Jun 15, 2020
CVE-2021-41819
HIGH7.5

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

ruby-lang / cgi+17
Network
Published Jan 1, 2022
CVE-2021-41817
HIGH7.5

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

ruby-lang / date+18
Network
Published Jan 1, 2022
CVE-2021-4166
HIGH7.1

vim is vulnerable to Out-of-bounds Read

vim / vim+25
Local
Published Dec 25, 2021
CVE-2023-34256
MEDIUM5.5

An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access.

linux / linux_kernel+4
Local
Published May 31, 2023
CVE-2024-23301
MEDIUM5.5

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

relax-and-recover / relax-and-recover+4
Local
Published Jan 12, 2024