Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2019-12303
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd…
Rancher
after 2.2.3
MEDIUM 5.9
CVE-2019-3684
SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that do…
Manager
after 4.0.7
HIGH 8.1
CVE-2019-6287
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have bee…
Rancher
after 2.1.5
HIGH 8.8
CVE-2018-20321
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service accou…
Rancher
after 2.1.5
HIGH 7.8
CVE-2018-17957
The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, a…
Repository Mirroring Tool
1.1.2+
CRITICAL 9.8
CVE-2018-12470
A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected relea…
Subscription Management Tool
3.0.37+
CRITICAL 9.1
CVE-2018-12472
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux…
Subscription Management Tool
3.0.37+
HIGH 8.1
CVE-2018-12471
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing …
Subscription Management Tool
3.0.37+
HIGH 7.8
CVE-2018-16588
Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux E…
Shadow
after 4.5-5.39
CRITICAL 9.8
CVE-2016-1000030
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_cr…
Linux Enterprise Server
2.11.0+
MEDIUM 5.3
CVE-2011-4190
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. Thi…
Suse Linux Enterprise Desktop
Mitigation only
CRITICAL 9.8
CVE-2011-3172
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are S…
Suse Linux Enterprise Server
12.0+
HIGH 8.8
CVE-2011-0467
A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute ar…
Studio Onsite
1.0.3-0.18.1 / 1.1.2-0.25.1+
HIGH 8.8
CVE-2018-8059
The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Mi…
Portus
Mitigation only
MEDIUM 5.3
CVE-2017-14804
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of …
Linux Enterprise Software Development Kit
Mitigation only
MEDIUM 6.5
CVE-2017-15638
The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 SP2; bef…
Susefirewall2
Mitigation only
MEDIUM 5.4
CVE-2017-14621
Portus 2.2.0 has XSS via the Team field, related to typeahead.
Portus
Patch available
CRITICAL 9.8
CVE-2011-0469
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
Opensuse
Patch available
HIGH 8.8
CVE-2017-7297
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/s…
Rancher
1.2.4 / 1.3.5+
HIGH 7.8
CVE-2016-1602
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise De…
Linux Enterprise Desktop
Mitigation only
MEDIUM 5.5
CVE-2015-8929
Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denia…
Linux Enterprise Desktop
after 3.1.901a
CRITICAL 9.8
CVE-2016-1601
yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST ins…
Yast2
Mitigation only
HIGH 7.5
CVE-2014-0222
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a la…
Linux Enterprise Server
after 1.7.1
HIGH 7.5
CVE-2011-4192
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execu…
Kiwi
after 4.85
HIGH 7.5
CVE-2011-4195
kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to exec…
Kiwi
after 4.98.04
HIGH 7.5
CVE-2011-3180
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to exec…
Kiwi
after 4.98.07
HIGH 10.0
CVE-2013-3712
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vector…
Studio Extension For System Z
No fix yet
MEDIUM 5.8
CVE-2012-0435
SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a craf…
Webyast
Mitigation only
HIGH 7.5
CVE-2011-2660
The modify_resolvconf_suse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to ex…
Vpnc
after 0.5.1
HIGH 7.5
CVE-2010-0230
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers…
Opensuse
Mitigation only