Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rancher HIGH 8.8
CVE-2019-12303

In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd…

Fix: after 2.2.3
Fix from $1,950 2019-06-06
Manager MEDIUM 5.9
CVE-2019-3684

SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that do…

Fix: after 4.0.7
Fix from $1,600 2019-05-13
Rancher HIGH 8.1
CVE-2019-6287

In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have bee…

Fix: after 2.1.5
Fix from $1,950 2019-04-10
Rancher HIGH 8.8
CVE-2018-20321

An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service accou…

Fix: after 2.1.5
Fix from $1,950 2019-04-10
Repository Mirroring Tool HIGH 7.8
CVE-2018-17957

The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, a…

Fix: 1.1.2+
Fix from $1,950 2018-12-26
Subscription Management Tool CRITICAL 9.8
CVE-2018-12470

A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected relea…

Fix: 3.0.37+
Fix from $2,300 2018-10-04
Subscription Management Tool CRITICAL 9.1
CVE-2018-12472

A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux…

Fix: 3.0.37+
Fix from $2,300 2018-10-04
Subscription Management Tool HIGH 8.1
CVE-2018-12471

A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing …

Fix: 3.0.37+
Fix from $1,950 2018-10-04
Shadow HIGH 7.8
CVE-2018-16588

Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux E…

Fix: after 4.5-5.39
Fix from $1,950 2018-09-26
Linux Enterprise Server CRITICAL 9.8
CVE-2016-1000030

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_cr…

Fix: 2.11.0+
Fix from $2,300 2018-09-05
Suse Linux Enterprise Desktop MEDIUM 5.3
CVE-2011-4190

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. Thi…

Mitigation only
Fix from $1,600 2018-06-08
Suse Linux Enterprise Server CRITICAL 9.8
CVE-2011-3172

A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are S…

Fix: 12.0+
Fix from $2,300 2018-06-08
Studio Onsite HIGH 8.8
CVE-2011-0467

A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute ar…

Fix: 1.0.3-0.18.1 / 1.1.2-0.25.1+
Fix from $1,950 2018-06-07
Portus HIGH 8.8
CVE-2018-8059

The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Mi…

Mitigation only
Fix from $1,950 2018-03-11
Linux Enterprise Software Development Kit MEDIUM 5.3
CVE-2017-14804

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of …

Mitigation only
Fix from $1,600 2018-03-01
Susefirewall2 MEDIUM 6.5
CVE-2017-15638

The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 SP2; bef…

Mitigation only
Fix from $1,600 2017-11-10
Portus MEDIUM 5.4
CVE-2017-14621

Portus 2.2.0 has XSS via the Team field, related to typeahead.

Patch available
Fix from $1,600 2017-09-20
Opensuse CRITICAL 9.8
CVE-2011-0469

Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.

Patch available
Fix from $2,300 2017-08-17
Rancher HIGH 8.8
CVE-2017-7297

Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/s…

Fix: 1.2.4 / 1.3.5+
Fix from $1,950 2017-03-29
Linux Enterprise Desktop HIGH 7.8
CVE-2016-1602

A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise De…

Mitigation only
Fix from $1,950 2017-03-23
Linux Enterprise Desktop MEDIUM 5.5
CVE-2015-8929

Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denia…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Yast2 CRITICAL 9.8
CVE-2016-1601

yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST ins…

Mitigation only
Fix from $2,300 2016-04-26
Linux Enterprise Server HIGH 7.5
CVE-2014-0222

Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a la…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Kiwi HIGH 7.5
CVE-2011-4192

kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execu…

Fix: after 4.85
Fix from $1,950 2014-04-16
Kiwi HIGH 7.5
CVE-2011-4195

kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to exec…

Fix: after 4.98.04
Fix from $1,950 2014-04-16
Kiwi HIGH 7.5
CVE-2011-3180

kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to exec…

Fix: after 4.98.07
Fix from $1,950 2014-04-16
Studio Extension For System Z HIGH 10.0
CVE-2013-3712

SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vector…

No fix yet
Fix from $1,950 2014-02-26
Webyast MEDIUM 5.8
CVE-2012-0435

SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a craf…

Mitigation only
Fix from $1,600 2013-01-26
Vpnc HIGH 7.5
CVE-2011-2660

The modify_resolvconf_suse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to ex…

Fix: after 0.5.1
Fix from $1,950 2011-09-06
Opensuse HIGH 7.5
CVE-2010-0230

SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers…

Mitigation only
Fix from $1,950 2010-01-22