Skip to content
Noroxi

SUSE records

1,205 published records for vendor suse.

Researcher profile

Entered KEV
48 · 4%
Weaponized
63 · 5.2%
Pre-auth RCE
265
With a fix record
78.4%
Median publish → KEV
2796 days

All records

1,205 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerJun 23, 2015

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerFeb 5, 2014

  • Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    adobe · flash playerJul 8, 2015

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    oracle · jreJun 18, 2013

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    oracle · jreJun 7, 2012

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    oracle · jdkOct 19, 2011

  • Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    adobe · flash playerFeb 2, 2015

  • Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · flash playerMay 10, 2016

  • Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · flash playerJul 14, 2015

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    oracle · jdkApr 21, 2016

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers t

    CriticalCVSS 9.8KEVWeaponizedEPSS 91%

    oracle · jreOct 16, 2012

  • Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    adobe · flash playerApr 13, 2011

  • Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu

    CriticalCVSS 9.8KEVWeaponizedEPSS 86%

    adobe · flash playerJan 23, 2015

  • The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor

    HighCVSS 8.4KEVWeaponizedEPSS 97%

    imagemagick · imagemagickMay 5, 2016

  • The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot

    HighCVSS 8.8KEVWeaponizedEPSS 83%

    adobe · acrobatJan 13, 2010

  • Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, an

    HighCVSS 7.5KEVWeaponizedEPSS 96%

    rubyonrails · railsFeb 15, 2016

  • A local privilege escalation vulnerability was found on polkit's pkexec utility.

    HighCVSS 7.8KEVWeaponizedEPSS 94%

    polkit project · polkitJan 28, 2022

  • Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbit

    CriticalCVSS 9.8KEVWeaponizedEPSS 67%

    adobe · acrobatMay 16, 2013

  • Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c

    HighCVSS 7.8KEVWeaponizedEPSS 87%

    adobe · acrobatFeb 13, 2013

  • Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,

    HighCVSS 7.8KEVWeaponizedEPSS 83%

    adobe · airJun 8, 2010

  • Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before

    HighCVSS 7.8KEVWeaponizedEPSS 82%

    adobe · acrobatDec 14, 2009

  • Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper

    HighCVSS 8.8KEVWeaponizedEPSS 69%

    mozilla · firefoxJun 25, 2013