Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2022-31248 A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to disc… Manager Server 4.1.46-1 / 4.2.37-1+ Fix from $1,6002022-06-22 HIGH 7.5 CVE-2022-21952 A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote atta… Manager Server 4.1.46 / 4.2.37+ Fix from $1,9502022-06-22 MEDIUM 6.8 CVE-2022-21951 A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network d… Rancher 2.5.14 / 2.6.5+ Fix from $1,6002022-05-25 HIGH 7.2 CVE-2021-36784 A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affec… Rancher 2.5.13 / 2.6.4+ Fix from $1,9502022-05-02 MEDIUM 5.4 CVE-2021-4200 A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. … Rancher 2.5.13 / 2.6.4+ Fix from $1,6002022-05-02 HIGH 7.5 CVE-2021-36778 A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to thei… Rancher 2.5.12 / 2.6.3+ Fix from $1,9502022-05-02 HIGH 8.8 CVE-2022-21947 A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API… Rancher Desktop 1.2.1+ Fix from $1,9502022-04-01 MEDIUM 6.5 CVE-2021-32001 K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keyin… Rancher K3s Mitigation only Fix from $1,6002021-07-28 HIGH 7.1 CVE-2021-32000 A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Serve… Linux Enterprise Server Patch available Fix from $1,9502021-07-28 HIGH 7.8 CVE-2021-25321 A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenSta… Arpwatch 2.1a15+ Fix from $1,9502021-06-30 HIGH 7.8 CVE-2021-25314 A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterpris… Hawk2 2.6.3+ Fix from $1,9502021-04-14 MEDIUM 6.1 CVE-2021-25313 A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute Ja… Rancher 2.5.6+ Fix from $1,6002021-03-05 CRITICAL 9.3 CVE-2020-8028 A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy … Salt Netapi Client 0.16.0-4.14.1 / 0.17.0-3.3.2+ Fix from $2,3002020-09-17 CRITICAL 9.3 CVE-2020-8025 A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Ser… Linux Enterprise High Performance Computing No fix yet Fix from $2,3002020-08-07 HIGH 7.8 CVE-2020-8018 A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server … Linux Enterprise Desktop Mitigation only Fix from $1,9502020-05-04 HIGH 7.8 CVE-2018-17954 An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8… Openstack Cloud Mitigation only Fix from $1,9502020-04-03 HIGH 7.8 CVE-2019-18897 A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; … Linux Enterprise Server Mitigation only Fix from $1,9502020-03-02 HIGH 8.1 CVE-2017-14807 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite a… Studio Onsite after 1.3.17-56.6.3 Fix from $1,9502020-01-27 MEDIUM 5.9 CVE-2017-14806 A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the reposit… Studio Onsite after 1.3.17-56.6.3 Fix from $1,6002020-01-27 HIGH 7.5 CVE-2018-12476 Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with contro… Obs Service Tar Scm 0.9.2.1537788075.fefaa74+ Fix from $1,9502020-01-27 HIGH 7.8 CVE-2019-3693 A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1… Mailman 2.1.15-9.6.15.1 / 2.1.17-3.11.1+ Fix from $1,9502020-01-24 HIGH 7.8 CVE-2019-3692 The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via sym… Inn after 2.6.2-2.2 Fix from $1,9502020-01-24 HIGH 7.8 CVE-2019-18898 UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local a… Trousers 0.3.14-6.3.1 / 0.3.14-7.1+ Fix from $1,9502020-01-23 MEDIUM 6.1 CVE-2019-3686 openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through th… Openqa 2019-07-22+ Fix from $1,6002020-01-17 HIGH 8.8 CVE-2019-3683 The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/k… Openstack Cloud 2019-02-18+ Fix from $1,9502020-01-17 HIGH 7.8 CVE-2019-3682 The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node. Caas Platform Mitigation only Fix from $1,9502020-01-17 HIGH 7.1 CVE-2019-3688 The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterpris… Suse Linux Enterprise Server Mitigation only Fix from $1,9502019-10-07 MEDIUM 6.1 CVE-2019-13209 Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Ranch… Rancher after 2.2.4 Fix from $1,6002019-09-04 CRITICAL 9.8 CVE-2019-11202 An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When… Rancher after 2.2.1 Fix from $2,3002019-07-30 HIGH 8.8 CVE-2019-12274 In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node … Rancher after 2.2.3 Fix from $1,9502019-06-06