Linux Enterprise Desktop
461 CVEs tracked. 36 of them are in CISA KEV.
This hub aggregates every CVE we track for Linux Enterprise Desktop, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Linux Enterprise Desktop CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 461 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical136
- High109
- Medium173
- Low43
Latest CVEs
The 15 most recently published vulnerabilities affecting Linux Enterprise Desktop.
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
- CVE-2025-32463Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.9.3
- CVE-2022-27239In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.7.8
- CVE-2021-4034A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users acc...7.8
- CVE-2018-10195lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.7.1
- CVE-2020-8018User owned /etc in SLES15-SP1-CHOST-BYOS8.4
- CVE-2014-1947Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrar...7.8
- CVE-2006-7246NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.6.8
- CVE-2015-5239Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.6.5
- CVE-2019-11038Uninitialized read in gdImageCreateFromXbm5.3
- CVE-2017-16232LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third...7.5
- CVE-2018-19540An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900...8.8
- CVE-2018-19541An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900...8.8
- CVE-2018-19539An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.6.5
- CVE-2018-19543An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.7.8
Product grouping is registry-driven, with AI assist and human review. How it works