Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-32182 A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux … Leap No fix yet Fix from $1,9502023-09-19 HIGH 7.8 CVE-2023-32183 Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root Th… Tumbleweed No fix yet Fix from $1,9502023-07-07 MEDIUM 5.4 CVE-2018-12475 A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows a… Open Build Service Mitigation only Fix from $1,6002020-09-01 CRITICAL 9.8 CVE-2019-18902 A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo… Leap Mitigation only Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2019-18903 A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo… Leap Mitigation only Fix from $2,3002020-03-02 MEDIUM 5.5 CVE-2019-18901 A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE … Leap Mitigation only Fix from $1,6002020-03-02 MEDIUM 6.5 CVE-2018-12478 A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affe… Open Build Service Mitigation only Fix from $1,6002018-10-09 CRITICAL 9.8 CVE-2017-9269 In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down… Libzypp Mitigation only Fix from $2,3002018-03-01 CRITICAL 9.1 CVE-2017-9270 In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database. Cryptctl Mitigation only Fix from $2,3002018-03-01 HIGH 7.5 CVE-2017-6318 saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet. Leap Mitigation only Fix from $1,9502017-03-20 HIGH 7.8 CVE-2015-5228 The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing f… Opensuse Mitigation only Fix from $1,9502016-06-07 MEDIUM 6.2 CVE-2016-3186 Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash)… Opensuse Mitigation only Fix from $1,6002016-04-19 MEDIUM 5.5 CVE-2016-4036 The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows loca… Leap Mitigation only Fix from $1,6002016-04-18 HIGH 7.8 CVE-2015-7552 Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of se… Opensuse Mitigation only Fix from $1,9502016-04-18 MEDIUM 6.2 CVE-2015-5969 The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 4… Leap Mitigation only Fix from $1,6002016-04-08 HIGH 7.5 CVE-2015-8078 Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i… Leap Mitigation only Fix from $1,9502015-12-03 HIGH 7.5 CVE-2015-8076 The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain s… Leap Mitigation only Fix from $1,9502015-12-03 HIGH 9.3 CVE-2015-7805EPSS 13% Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF f… Opensuse No fix yet Fix from $1,9502015-11-17 MEDIUM 5.0 CVE-2015-5185 The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer deref… Opensuse No fix yet Fix from $1,6002015-09-28 MEDIUM 5.0 CVE-2015-4144 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain t… Opensuse Mitigation only Fix from $1,6002015-06-15 HIGH 9.3 CVE-2015-0492 Unspecified vulnerability in Oracle Java SE 7u76 and 8u40, and JavaFX 2.2.76, allows remote attackers to affect confidentiality, integrity, and avail… Opensuse Mitigation only Fix from $1,9502015-04-16 MEDIUM 5.0 CVE-2014-3619 The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" frag… Opensuse Mitigation only Fix from $1,6002015-03-27 HIGH 7.5 CVE-2015-1182 The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointe… Opensuse Mitigation only Fix from $1,9502015-01-27 HIGH 7.2 CVE-2014-8148 The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system… Opensuse Mitigation only Fix from $1,9502015-01-26 HIGH 10.0 CVE-2014-2977EPSS 7% Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote a… Opensuse Mitigation only Fix from $1,9502014-06-11 HIGH 7.2 CVE-2013-1090 The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, … Opensuse Mitigation only Fix from $1,9502013-12-06 HIGH 7.8 CVE-2012-0425 LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows contex… Opensuse Mitigation only Fix from $1,9502013-12-02 HIGH 7.2 CVE-2012-0427 yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain pri… Opensuse No fix yet Fix from $1,9502013-12-02 MEDIUM 6.9 CVE-2011-0468 The aaa_base package before 11.3-8.9.1 in SUSE openSUSE 11.3, and before 11.4-54.62.1 in openSUSE 11.4, allows local users to gain privileges via she… Opensuse Mitigation only Fix from $1,6002011-04-04 MEDIUM 6.3 CVE-2011-0461 /etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local user… Opensuse Mitigation only Fix from $1,6002011-04-04