CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

suse

suse_linux_enterprise_server

24 known vulnerabilities · sorted by CVSS score

CVE-2020-5504
HIGH8.8

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

phpmyadmin / phpmyadmin+3
Network
Published Jan 9, 2020
Page 1 of 2
CVE-2020-6422
HIGH8.8

Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+8
Network
Published Mar 23, 2020
CVE-2020-6424
HIGH8.8

Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+8
Network
Published Mar 23, 2020
CVE-2018-19655
HIGH8.8

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

dcraw_project / dcraw+5
Network
Published Nov 29, 2018
CVE-2020-6449
HIGH8.8

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+8
Network
Published Mar 23, 2020
CVE-2020-6428
HIGH8.8

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+8
Network
Published Mar 23, 2020
CVE-2020-6429
HIGH8.8

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+8
Network
Published Mar 23, 2020
CVE-2020-6427
HIGH8.8

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+8
Network
Published Mar 23, 2020
CVE-2018-19052
HIGH7.5

An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.

lighttpd / lighttpd+12
Network
Published Nov 7, 2018
CVE-2018-12116
HIGH7.5

Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.

nodejs / node.js+8
Network
Published Nov 28, 2018
CVE-2018-12122
HIGH7.5

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

nodejs / node.js+8
Network
Published Nov 28, 2018
CVE-2017-14798
HIGH7.3

A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.

postgresql / postgresql+1
Local
Published Mar 1, 2018
CVE-2020-6426
MEDIUM6.5

Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+8
Network
Published Mar 23, 2020
CVE-2018-19208
MEDIUM6.5

In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.

libwpd_project / libwpd+2
Network
Published Nov 12, 2018
CVE-2020-15705
MEDIUM6.4

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

gnu / grub2+31
Local
Published Jul 29, 2020
CVE-2020-15706
MEDIUM6.4

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

gnu / grub2+35
Local
Published Jul 29, 2020
CVE-2011-4190
MEDIUM5.9

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).

suse / suse_linux_enterprise_desktop+3
Network
Published Jun 8, 2018
CVE-2020-15707
MEDIUM5.7

Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.

gnu / grub2+32
Local
Published Jul 29, 2020
CVE-2017-5753
MEDIUM5.6

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

intel / core_i5+999
Local
Published Jan 4, 2018
CVE-2011-3172
MEDIUM5.4

A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.

suse / suse_linux_enterprise_server
Network
Published Jun 8, 2018