Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2021-31998
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE…
Inn
2.6.2+
HIGH 7.8
CVE-2021-25319
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to es…
Factory
after 6.1.20-1.1
HIGH 7.0
CVE-2020-8032
A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue aff…
Cyrus Sasl
after 2.1.27
MEDIUM 6.6
CVE-2020-8027
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap …
Openldap2
2.4.46-lp151.10.18.1 / 2.4.46-lp152.14.9.1+
MEDIUM 5.4
CVE-2020-8031
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to…
Open Build Service
2.10.8+
HIGH 7.8
CVE-2020-8023
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux E…
Openldap2
2.4.26-0.74.13.1 / 2.4.41-18.71.2+
MEDIUM 5.4
CVE-2018-12475
A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows a…
Open Build Service
Mitigation only
HIGH 7.8
CVE-2020-8026
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local att…
Backports Sle
after 2.6.2-4.2
CRITICAL 9.8
CVE-2019-3681
A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software…
Osc
0.162.1-15.9.1 / 0.169.0+
HIGH 7.8
CVE-2020-8014
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local atta…
Leap
10.0.5-1.1+
MEDIUM 5.3
CVE-2020-8024
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local a…
Hylafax\+
5.6.1-lp151.3.7 / 7.0.2-lp152.2.1+
MEDIUM 5.9
CVE-2019-18905
A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allow…
Autoyast2
after 4.1.9-3.9.1
HIGH 7.5
CVE-2019-18904
A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Per…
Rmt Server
after 2.5.2-3.26.1
HIGH 7.0
CVE-2020-8016
A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Application…
Texlive Filesystem
2013.74-16.5.1 / 2017.135-lp151.8.3.1+
MEDIUM 6.3
CVE-2020-8017
A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Ap…
Texlive Filesystem
2013.74-16.5.1 / 2017.135-lp151.8.3.1+
HIGH 7.8
CVE-2019-3695
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Lin…
Pcp
3.11.9-5.8.1 / 3.11.9-6.14.1+
HIGH 7.3
CVE-2019-3696
A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computi…
Pcp
3.11.9-5.8.1 / 3.11.9-6.14.1+
CRITICAL 9.8
CVE-2019-18902
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo…
Leap
Mitigation only
CRITICAL 9.8
CVE-2019-18903
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remo…
Leap
Mitigation only
MEDIUM 5.5
CVE-2019-18901
A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE …
Leap
Mitigation only
HIGH 7.5
CVE-2020-7217
An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sendi…
Wicked
after 0.6.55
HIGH 7.5
CVE-2020-7216
An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 p…
Wicked
after 0.6.55
HIGH 7.8
CVE-2019-3694
A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from us…
Munin
after 2.0.49-4.2
HIGH 7.8
CVE-2019-3691
A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attack…
Munge
0.5.13-4.3.1 / 0.5.13-6.1+
HIGH 7.7
CVE-2019-3685
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary
Open Build Service
0.165.4+
HIGH 8.1
CVE-2018-20106
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backtic…
Yast2 Printer
after 4.0.2
HIGH 7.8
CVE-2018-17956
In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samb…
Yast2 Samba Provision
after 1.0.1
MEDIUM 5.5
CVE-2018-17955
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection
Yast2 Multipath
4.1.1+
HIGH 7.8
CVE-2018-19636
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides…
Supportutils
3.1-5.7.1+
HIGH 7.8
CVE-2018-19639
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with…
Supportutils
3.1-5.7.1+