Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Leap HIGH 7.8
CVE-2023-32182

A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux …

No fix yet
Fix from $1,950 2023-09-19
Tumbleweed HIGH 7.8
CVE-2023-32183

Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root Th…

No fix yet
Fix from $1,950 2023-07-07
Open Build Service MEDIUM 5.4
CVE-2018-12475

A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows a…

Mitigation only
Fix from $1,600 2020-09-01
Leap CRITICAL 9.8
CVE-2019-18902

A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo…

Mitigation only
Fix from $2,300 2020-03-02
Leap CRITICAL 9.8
CVE-2019-18903

A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo…

Mitigation only
Fix from $2,300 2020-03-02
Leap MEDIUM 5.5
CVE-2019-18901

A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE …

Mitigation only
Fix from $1,600 2020-03-02
Open Build Service MEDIUM 6.5
CVE-2018-12478

A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affe…

Mitigation only
Fix from $1,600 2018-10-09
Libzypp CRITICAL 9.8
CVE-2017-9269

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down…

Mitigation only
Fix from $2,300 2018-03-01
Cryptctl CRITICAL 9.1
CVE-2017-9270

In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.

Mitigation only
Fix from $2,300 2018-03-01
Leap HIGH 7.5
CVE-2017-6318

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

Mitigation only
Fix from $1,950 2017-03-20
Opensuse HIGH 7.8
CVE-2015-5228

The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing f…

Mitigation only
Fix from $1,950 2016-06-07
Opensuse MEDIUM 6.2
CVE-2016-3186

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash)…

Mitigation only
Fix from $1,600 2016-04-19
Leap MEDIUM 5.5
CVE-2016-4036

The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows loca…

Mitigation only
Fix from $1,600 2016-04-18
Opensuse HIGH 7.8
CVE-2015-7552

Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2016-04-18
Leap MEDIUM 6.2
CVE-2015-5969

The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 4…

Mitigation only
Fix from $1,600 2016-04-08
Leap HIGH 7.5
CVE-2015-8078

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i…

Mitigation only
Fix from $1,950 2015-12-03
Leap HIGH 7.5
CVE-2015-8076

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain s…

Mitigation only
Fix from $1,950 2015-12-03
Opensuse HIGH 9.3
CVE-2015-7805EPSS 13%

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF f…

No fix yet
Fix from $1,950 2015-11-17
Opensuse MEDIUM 5.0
CVE-2015-5185

The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer deref…

No fix yet
Fix from $1,600 2015-09-28
Opensuse MEDIUM 5.0
CVE-2015-4144

The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain t…

Mitigation only
Fix from $1,600 2015-06-15
Opensuse HIGH 9.3
CVE-2015-0492

Unspecified vulnerability in Oracle Java SE 7u76 and 8u40, and JavaFX 2.2.76, allows remote attackers to affect confidentiality, integrity, and avail…

Mitigation only
Fix from $1,950 2015-04-16
Opensuse MEDIUM 5.0
CVE-2014-3619

The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" frag…

Mitigation only
Fix from $1,600 2015-03-27
Opensuse HIGH 7.5
CVE-2015-1182

The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointe…

Mitigation only
Fix from $1,950 2015-01-27
Opensuse HIGH 7.2
CVE-2014-8148

The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system…

Mitigation only
Fix from $1,950 2015-01-26
Opensuse HIGH 10.0
CVE-2014-2977EPSS 7%

Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote a…

Mitigation only
Fix from $1,950 2014-06-11
Opensuse HIGH 7.2
CVE-2013-1090

The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, …

Mitigation only
Fix from $1,950 2013-12-06
Opensuse HIGH 7.8
CVE-2012-0425

LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows contex…

Mitigation only
Fix from $1,950 2013-12-02
Opensuse HIGH 7.2
CVE-2012-0427

yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain pri…

No fix yet
Fix from $1,950 2013-12-02
Opensuse MEDIUM 6.9
CVE-2011-0468

The aaa_base package before 11.3-8.9.1 in SUSE openSUSE 11.3, and before 11.4-54.62.1 in openSUSE 11.4, allows local users to gain privileges via she…

Mitigation only
Fix from $1,600 2011-04-04
Opensuse MEDIUM 6.3
CVE-2011-0461

/etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local user…

Mitigation only
Fix from $1,600 2011-04-04