Записи SUSE
1 205 опубликованных записей вендора suse.
Профиль для исследователя
- Попали в KEV
- 48 · 4 %
- С эксплойтом
- 63 · 5,2 %
- Pre-auth RCE
- 265
- С записью об исправлении
- 78,4 %
- Медиана: публикация → KEV
- 2796 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer97
- CWE-416 Use After Free68
- CWE-787 Out-of-bounds Write61
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor42
- CWE-476 NULL Pointer Dereference37
- CWE-20 Improper Input Validation35
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 205 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2014-0497Готовый эксплойт | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Критическая9,8 | KEV | 99,9 % | 5 февр. 2014 г. |
99Срочно | CVE-2015-5119Готовый эксплойт | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Критическая9,8 | KEV | 99,3 % | 8 июл. 2015 г. |
99Срочно | CVE-2013-2465Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Критическая9,8 | KEV | 98,8 % | 18 июн. 2013 г. |
98Срочно | CVE-2012-0507Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Критическая9,8 | KEV | 98,1 % | 7 июн. 2012 г. |
98Срочно | CVE-2011-3544Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Критическая9,8 | KEV | 96,7 % | 19 окт. 2011 г. |
98Срочно | CVE-2015-0313Готовый эксплойт | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Критическая9,8 | KEV | 95,3 % | 2 февр. 2015 г. |
97Срочно | CVE-2016-4117Готовый эксплойт | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Критическая9,8 | KEV | 94,4 % | 10 мая 2016 г. |
97Срочно | CVE-2015-5122Готовый эксплойт | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Критическая9,8 | KEV | 94,0 % | 14 июл. 2015 г. |
97Срочно | CVE-2016-3427Готовый эксплойт | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Критическая9,8 | KEV | 92,3 % | 21 апр. 2016 г. |
96Срочно | CVE-2012-5076Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers toracle · jre · CWE-284 | Критическая9,8 | KEV | 91,3 % | 16 окт. 2012 г. |
95Срочно | CVE-2011-0611Готовый эксплойт | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | Высокая8,8 | KEV | 99,4 % | 13 апр. 2011 г. |
95Срочно | CVE-2015-0311Готовый эксплойт | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throuadobe · flash player | Критическая9,8 | KEV | 85,6 % | 23 янв. 2015 г. |
92Срочно | CVE-2016-3714Готовый эксплойт | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | Высокая8,4 | KEV | 97,5 % | 5 мая 2016 г. |
90Срочно | CVE-2009-3953Готовый эксплойт | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | Высокая8,8 | KEV | 83,2 % | 13 янв. 2010 г. |
89Срочно | CVE-2016-0752Готовый эксплойт | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, anrubyonrails · rails · CWE-22 | Высокая7,5 | KEV | 95,5 % | 15 февр. 2016 г. |
89Срочно | CVE-2021-4034Готовый эксплойт | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | Высокая7,8 | KEV | 94,3 % | 28 янв. 2022 г. |
89Срочно | CVE-2013-2729Готовый эксплойт | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitadobe · acrobat · CWE-190 | Критическая9,8 | KEV | 66,6 % | 16 мая 2013 г. |
87Срочно | CVE-2013-0640Готовый эксплойт | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | Высокая7,8 | KEV | 86,9 % | 13 февр. 2013 г. |
86Срочно | CVE-2010-1297Готовый эксплойт | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,adobe · air · CWE-787 | Высокая7,8 | KEV | 82,5 % | 8 июн. 2010 г. |
86Срочно | CVE-2009-4324Готовый эксплойт | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before adobe · acrobat · CWE-416 | Высокая7,8 | KEV | 81,9 % | 14 дек. 2009 г. |
86Срочно | CVE-2013-1690Готовый эксплойт | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | Высокая8,8 | KEV | 69,0 % | 25 июн. 2013 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-049799Срочно
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player5 февр. 2014 г.
- CVE-2015-511999Срочно
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · flash player8 июл. 2015 г.
- CVE-2013-246599Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jre18 июн. 2013 г.
- CVE-2012-050798Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %oracle · jre7 июн. 2012 г.
- CVE-2011-354498Срочно
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk19 окт. 2011 г.
- CVE-2015-031398Срочно
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %adobe · flash player2 февр. 2015 г.
- CVE-2016-411797Срочно
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player10 мая 2016 г.
- CVE-2015-512297Срочно
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player14 июл. 2015 г.
- CVE-2016-342797Срочно
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %oracle · jdk21 апр. 2016 г.
- CVE-2012-507696Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers t
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 91 %oracle · jre16 окт. 2012 г.
- CVE-2011-061195Срочно
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %adobe · flash player13 апр. 2011 г.
- CVE-2015-031195Срочно
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %adobe · flash player23 янв. 2015 г.
- CVE-2016-371492Срочно
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 97 %imagemagick · imagemagick5 мая 2016 г.
- CVE-2009-395390Срочно
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %adobe · acrobat13 янв. 2010 г.
- CVE-2016-075289Срочно
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, an
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 96 %rubyonrails · rails15 февр. 2016 г.
- CVE-2021-403489Срочно
A local privilege escalation vulnerability was found on polkit's pkexec utility.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 94 %polkit project · polkit28 янв. 2022 г.
- CVE-2013-272989Срочно
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 67 %adobe · acrobat16 мая 2013 г.
- CVE-2013-064087Срочно
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 87 %adobe · acrobat13 февр. 2013 г.
- CVE-2010-129786Срочно
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 83 %adobe · air8 июн. 2010 г.
- CVE-2009-432486Срочно
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 82 %adobe · acrobat14 дек. 2009 г.
- CVE-2013-169086Срочно
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %mozilla · firefox25 июн. 2013 г.