Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2018-19637
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symli…
Supportutils
3.1-5.7.1+
MEDIUM 5.5
CVE-2018-19640
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638…
Supportutils
3.1-5.7.1+
CRITICAL 9.8
CVE-2018-12474
Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the cu…
Tar Scm
0.9.3+
HIGH 7.5
CVE-2018-12479
A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected rele…
Open Build Service
after 2.9.4
MEDIUM 6.5
CVE-2018-12478
A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affe…
Open Build Service
Mitigation only
HIGH 7.5
CVE-2018-12473
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the curren…
Open Build Service
after 0.9.1
HIGH 7.8
CVE-2018-7685
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call woul…
Libzypp
17.5.0+
MEDIUM 6.5
CVE-2018-12466
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
Open Build Service
9.2.4+
MEDIUM 6.5
CVE-2018-12467
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe…
Open Build Service
2.9.4+
CRITICAL 9.8
CVE-2011-4183
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2…
Open Build Service
2.1.16+
HIGH 8.1
CVE-2011-4182
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. …
Sysconfig
after 0.83.7
HIGH 7.5
CVE-2011-4181
A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases…
Open Build Service
2.1.16+
CRITICAL 9.8
CVE-2014-0593
The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1…
Open Build Service
1.1+
HIGH 8.8
CVE-2014-0594
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without …
Open Build Service
2.4.6+
HIGH 7.8
CVE-2014-5220
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local a…
Opensuse
3.3.3+
MEDIUM 6.5
CVE-2013-3703
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or…
Open Build Service
2.4.4+
MEDIUM 6.5
CVE-2018-7688
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in pr…
Open Build Service
2.9.3+
MEDIUM 6.5
CVE-2018-7689
Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify pa…
Open Build Service
2.9.3+
HIGH 8.8
CVE-2011-3178
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e…
Open Build Service
2.3.0+
HIGH 7.8
CVE-2015-0796
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l…
Open Buildservice
2.4.8 / 2.5.7+
HIGH 7.8
CVE-2017-9274
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files w…
Obs Service Source Validator
0.7+
CRITICAL 9.8
CVE-2017-9269
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down…
Libzypp
Mitigation only
CRITICAL 9.1
CVE-2017-9270
In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.
Cryptctl
Mitigation only
HIGH 8.1
CVE-2017-7435
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malic…
Libzypp
after 16.15.2
HIGH 8.1
CVE-2017-7436
In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malic…
Libzypp
after 16.15.2
HIGH 7.5
CVE-2017-5188
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director…
Open Build Service
after 2.7.3
MEDIUM 6.5
CVE-2017-9268
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated user…
Open Build Service
after 2.8.2
HIGH 7.5
CVE-2014-3462
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and addin…
Leap
1.7.5+
MEDIUM 6.1
CVE-2015-8864
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web scr…
Leap
after 1.0.8
MEDIUM 6.1
CVE-2016-4068
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web scr…
Leap
after 1.0.8