Vulnerability index

Browse CVEs

159 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Inn HIGH 7.8
CVE-2021-31998

A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE…

Fix: 2.6.2+
Fix from $1,950 2021-06-10
Factory HIGH 7.8
CVE-2021-25319

A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to es…

Fix: after 6.1.20-1.1
Fix from $1,950 2021-05-05
Cyrus Sasl HIGH 7.0
CVE-2020-8032

A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue aff…

Fix: after 2.1.27
Fix from $1,950 2021-02-25
Openldap2 MEDIUM 6.6
CVE-2020-8027

A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap …

Fix: 2.4.46-lp151.10.18.1 / 2.4.46-lp152.14.9.1+
Fix from $1,600 2021-02-11
Open Build Service MEDIUM 5.4
CVE-2020-8031

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to…

Fix: 2.10.8+
Fix from $1,600 2021-02-11
Openldap2 HIGH 7.8
CVE-2020-8023

A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux E…

Fix: 2.4.26-0.74.13.1 / 2.4.41-18.71.2+
Fix from $1,950 2020-09-01
Open Build Service MEDIUM 5.4
CVE-2018-12475

A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows a…

Mitigation only
Fix from $1,600 2020-09-01
Backports Sle HIGH 7.8
CVE-2020-8026

A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local att…

Fix: after 2.6.2-4.2
Fix from $1,950 2020-08-07
Osc CRITICAL 9.8
CVE-2019-3681

A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software…

Fix: 0.162.1-15.9.1 / 0.169.0+
Fix from $2,300 2020-06-29
Leap HIGH 7.8
CVE-2020-8014

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local atta…

Fix: 10.0.5-1.1+
Fix from $1,950 2020-06-29
Hylafax\+ MEDIUM 5.3
CVE-2020-8024

A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local a…

Fix: 5.6.1-lp151.3.7 / 7.0.2-lp152.2.1+
Fix from $1,600 2020-06-29
Autoyast2 MEDIUM 5.9
CVE-2019-18905

A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allow…

Fix: after 4.1.9-3.9.1
Fix from $1,600 2020-04-03
Rmt Server HIGH 7.5
CVE-2019-18904

A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Per…

Fix: after 2.5.2-3.26.1
Fix from $1,950 2020-04-03
Texlive Filesystem HIGH 7.0
CVE-2020-8016

A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Application…

Fix: 2013.74-16.5.1 / 2017.135-lp151.8.3.1+
Fix from $1,950 2020-04-02
Texlive Filesystem MEDIUM 6.3
CVE-2020-8017

A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Ap…

Fix: 2013.74-16.5.1 / 2017.135-lp151.8.3.1+
Fix from $1,600 2020-04-02
Pcp HIGH 7.8
CVE-2019-3695

A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Lin…

Fix: 3.11.9-5.8.1 / 3.11.9-6.14.1+
Fix from $1,950 2020-03-03
Pcp HIGH 7.3
CVE-2019-3696

A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computi…

Fix: 3.11.9-5.8.1 / 3.11.9-6.14.1+
Fix from $1,950 2020-03-03
Leap CRITICAL 9.8
CVE-2019-18902

A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo…

Mitigation only
Fix from $2,300 2020-03-02
Leap CRITICAL 9.8
CVE-2019-18903

A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo…

Mitigation only
Fix from $2,300 2020-03-02
Leap MEDIUM 5.5
CVE-2019-18901

A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE …

Mitigation only
Fix from $1,600 2020-03-02
Wicked HIGH 7.5
CVE-2020-7217

An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sendi…

Fix: after 0.6.55
Fix from $1,950 2020-02-11
Wicked HIGH 7.5
CVE-2020-7216

An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 p…

Fix: after 0.6.55
Fix from $1,950 2020-02-05
Munin HIGH 7.8
CVE-2019-3694

A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from us…

Fix: after 2.0.49-4.2
Fix from $1,950 2020-01-24
Munge HIGH 7.8
CVE-2019-3691

A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attack…

Fix: 0.5.13-4.3.1 / 0.5.13-6.1+
Fix from $1,950 2020-01-23
Open Build Service HIGH 7.7
CVE-2019-3685

Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary

Fix: 0.165.4+
Fix from $1,950 2019-11-05
Yast2 Printer HIGH 8.1
CVE-2018-20106

In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backtic…

Fix: after 4.0.2
Fix from $1,950 2019-03-15
Yast2 Samba Provision HIGH 7.8
CVE-2018-17956

In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samb…

Fix: after 1.0.1
Fix from $1,950 2019-03-15
Yast2 Multipath MEDIUM 5.5
CVE-2018-17955

In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection

Fix: 4.1.1+
Fix from $1,600 2019-03-15
Supportutils HIGH 7.8
CVE-2018-19636

Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides…

Fix: 3.1-5.7.1+
Fix from $1,950 2019-03-05
Supportutils HIGH 7.8
CVE-2018-19639

If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with…

Fix: 3.1-5.7.1+
Fix from $1,950 2019-03-05