Vulnerability index

Browse CVEs

159 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Supportutils MEDIUM 5.5
CVE-2018-19637

Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symli…

Fix: 3.1-5.7.1+
Fix from $1,600 2019-03-05
Supportutils MEDIUM 5.5
CVE-2018-19640

If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638…

Fix: 3.1-5.7.1+
Fix from $1,600 2019-03-05
Tar Scm CRITICAL 9.8
CVE-2018-12474

Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the cu…

Fix: 0.9.3+
Fix from $2,300 2018-10-09
Open Build Service HIGH 7.5
CVE-2018-12479

A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected rele…

Fix: after 2.9.4
Fix from $1,950 2018-10-09
Open Build Service MEDIUM 6.5
CVE-2018-12478

A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affe…

Mitigation only
Fix from $1,600 2018-10-09
Open Build Service HIGH 7.5
CVE-2018-12473

A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the curren…

Fix: after 0.9.1
Fix from $1,950 2018-10-02
Libzypp HIGH 7.8
CVE-2018-7685

The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call woul…

Fix: 17.5.0+
Fix from $1,950 2018-08-31
Open Build Service MEDIUM 6.5
CVE-2018-12466

openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.

Fix: 9.2.4+
Fix from $1,600 2018-08-01
Open Build Service MEDIUM 6.5
CVE-2018-12467

Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe…

Fix: 2.9.4+
Fix from $1,600 2018-08-01
Open Build Service CRITICAL 9.8
CVE-2011-4183

A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2…

Fix: 2.1.16+
Fix from $2,300 2018-06-13
Sysconfig HIGH 8.1
CVE-2011-4182

Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. …

Fix: after 0.83.7
Fix from $1,950 2018-06-12
Open Build Service HIGH 7.5
CVE-2011-4181

A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases…

Fix: 2.1.16+
Fix from $1,950 2018-06-11
Open Build Service CRITICAL 9.8
CVE-2014-0593

The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1…

Fix: 1.1+
Fix from $2,300 2018-06-08
Open Build Service HIGH 8.8
CVE-2014-0594

In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without …

Fix: 2.4.6+
Fix from $1,950 2018-06-08
Opensuse HIGH 7.8
CVE-2014-5220

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local a…

Fix: 3.3.3+
Fix from $1,950 2018-06-08
Open Build Service MEDIUM 6.5
CVE-2013-3703

The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or…

Fix: 2.4.4+
Fix from $1,600 2018-06-08
Open Build Service MEDIUM 6.5
CVE-2018-7688

A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in pr…

Fix: 2.9.3+
Fix from $1,600 2018-06-07
Open Build Service MEDIUM 6.5
CVE-2018-7689

Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify pa…

Fix: 2.9.3+
Fix from $1,600 2018-06-07
Open Build Service HIGH 8.8
CVE-2011-3178

In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e…

Fix: 2.3.0+
Fix from $1,950 2018-03-20
Open Buildservice HIGH 7.8
CVE-2015-0796

In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l…

Fix: 2.4.8 / 2.5.7+
Fix from $1,950 2018-03-02
Obs Service Source Validator HIGH 7.8
CVE-2017-9274

A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files w…

Fix: 0.7+
Fix from $1,950 2018-03-01
Libzypp CRITICAL 9.8
CVE-2017-9269

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down…

Mitigation only
Fix from $2,300 2018-03-01
Cryptctl CRITICAL 9.1
CVE-2017-9270

In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.

Mitigation only
Fix from $2,300 2018-03-01
Libzypp HIGH 8.1
CVE-2017-7435

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malic…

Fix: after 16.15.2
Fix from $1,950 2018-03-01
Libzypp HIGH 8.1
CVE-2017-7436

In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malic…

Fix: after 16.15.2
Fix from $1,950 2018-03-01
Open Build Service HIGH 7.5
CVE-2017-5188

The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director…

Fix: after 2.7.3
Fix from $1,950 2018-03-01
Open Build Service MEDIUM 6.5
CVE-2017-9268

In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated user…

Fix: after 2.8.2
Fix from $1,600 2018-03-01
Leap HIGH 7.5
CVE-2014-3462

The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and addin…

Fix: 1.7.5+
Fix from $1,950 2017-08-07
Leap MEDIUM 6.1
CVE-2015-8864

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web scr…

Fix: after 1.0.8
Fix from $1,600 2017-04-13
Leap MEDIUM 6.1
CVE-2016-4068

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web scr…

Fix: after 1.0.8
Fix from $1,600 2017-04-13