Vulnerability index

Browse CVEs

159 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2018-19637 Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symli… Supportutils 3.1-5.7.1+ Fix from $1,6002019-03-05 MEDIUM 5.5 CVE-2018-19640 If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638… Supportutils 3.1-5.7.1+ Fix from $1,6002019-03-05 CRITICAL 9.8 CVE-2018-12474 Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the cu… Tar Scm 0.9.3+ Fix from $2,3002018-10-09 HIGH 7.5 CVE-2018-12479 A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected rele… Open Build Service after 2.9.4 Fix from $1,9502018-10-09 MEDIUM 6.5 CVE-2018-12478 A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affe… Open Build Service Mitigation only Fix from $1,6002018-10-09 HIGH 7.5 CVE-2018-12473 A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the curren… Open Build Service after 0.9.1 Fix from $1,9502018-10-02 HIGH 7.8 CVE-2018-7685 The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call woul… Libzypp 17.5.0+ Fix from $1,9502018-08-31 MEDIUM 6.5 CVE-2018-12466 openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links. Open Build Service 9.2.4+ Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-12467 Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe… Open Build Service 2.9.4+ Fix from $1,6002018-08-01 CRITICAL 9.8 CVE-2011-4183 A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2… Open Build Service 2.1.16+ Fix from $2,3002018-06-13 HIGH 8.1 CVE-2011-4182 Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. … Sysconfig after 0.83.7 Fix from $1,9502018-06-12 HIGH 7.5 CVE-2011-4181 A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases… Open Build Service 2.1.16+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2014-0593 The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1… Open Build Service 1.1+ Fix from $2,3002018-06-08 HIGH 8.8 CVE-2014-0594 In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without … Open Build Service 2.4.6+ Fix from $1,9502018-06-08 HIGH 7.8 CVE-2014-5220 The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local a… Opensuse 3.3.3+ Fix from $1,9502018-06-08 MEDIUM 6.5 CVE-2013-3703 The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or… Open Build Service 2.4.4+ Fix from $1,6002018-06-08 MEDIUM 6.5 CVE-2018-7688 A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in pr… Open Build Service 2.9.3+ Fix from $1,6002018-06-07 MEDIUM 6.5 CVE-2018-7689 Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify pa… Open Build Service 2.9.3+ Fix from $1,6002018-06-07 HIGH 8.8 CVE-2011-3178 In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e… Open Build Service 2.3.0+ Fix from $1,9502018-03-20 HIGH 7.8 CVE-2015-0796 In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l… Open Buildservice 2.4.8 / 2.5.7+ Fix from $1,9502018-03-02 HIGH 7.8 CVE-2017-9274 A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files w… Obs Service Source Validator 0.7+ Fix from $1,9502018-03-01 CRITICAL 9.8 CVE-2017-9269 In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down… Libzypp Mitigation only Fix from $2,3002018-03-01 CRITICAL 9.1 CVE-2017-9270 In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database. Cryptctl Mitigation only Fix from $2,3002018-03-01 HIGH 8.1 CVE-2017-7435 In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malic… Libzypp after 16.15.2 Fix from $1,9502018-03-01 HIGH 8.1 CVE-2017-7436 In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malic… Libzypp after 16.15.2 Fix from $1,9502018-03-01 HIGH 7.5 CVE-2017-5188 The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director… Open Build Service after 2.7.3 Fix from $1,9502018-03-01 MEDIUM 6.5 CVE-2017-9268 In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated user… Open Build Service after 2.8.2 Fix from $1,6002018-03-01 HIGH 7.5 CVE-2014-3462 The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and addin… Leap 1.7.5+ Fix from $1,9502017-08-07 MEDIUM 6.1 CVE-2015-8864 Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web scr… Leap after 1.0.8 Fix from $1,6002017-04-13 MEDIUM 6.1 CVE-2016-4068 Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web scr… Leap after 1.0.8 Fix from $1,6002017-04-13