Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Linux Enterprise Server CRITICAL 9.8
CVE-2026-25702

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via…

Mitigation only
Fix from $2,300 2026-03-05
Pam Config HIGH 7.8
CVE-2025-6018

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw all…

No fix yet
Fix from $1,950 2025-07-23
Linux Enterprise Module For Sap Applications HIGH 7.8
CVE-2022-45153

An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux En…

No fix yet
Fix from $1,950 2023-02-15
Rancher K3s MEDIUM 6.5
CVE-2021-32001

K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keyin…

Mitigation only
Fix from $1,600 2021-07-28
Linux Enterprise High Performance Computing CRITICAL 9.3
CVE-2020-8025

A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Ser…

No fix yet
Fix from $2,300 2020-08-07
Linux Enterprise Desktop HIGH 7.8
CVE-2020-8018

A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server …

Mitigation only
Fix from $1,950 2020-05-04
Openstack Cloud HIGH 7.8
CVE-2018-17954

An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8…

Mitigation only
Fix from $1,950 2020-04-03
Linux Enterprise Server HIGH 7.8
CVE-2019-18897

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; …

Mitigation only
Fix from $1,950 2020-03-02
Caas Platform HIGH 7.8
CVE-2019-3682

The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.

Mitigation only
Fix from $1,950 2020-01-17
Suse Linux Enterprise Server HIGH 7.1
CVE-2019-3688

The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterpris…

Mitigation only
Fix from $1,950 2019-10-07
Suse Linux Enterprise Desktop MEDIUM 5.3
CVE-2011-4190

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. Thi…

Mitigation only
Fix from $1,600 2018-06-08
Portus HIGH 8.8
CVE-2018-8059

The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Mi…

Mitigation only
Fix from $1,950 2018-03-11
Linux Enterprise Software Development Kit MEDIUM 5.3
CVE-2017-14804

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of …

Mitigation only
Fix from $1,600 2018-03-01
Susefirewall2 MEDIUM 6.5
CVE-2017-15638

The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 SP2; bef…

Mitigation only
Fix from $1,600 2017-11-10
Linux Enterprise Desktop HIGH 7.8
CVE-2016-1602

A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise De…

Mitigation only
Fix from $1,950 2017-03-23
Yast2 CRITICAL 9.8
CVE-2016-1601

yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST ins…

Mitigation only
Fix from $2,300 2016-04-26
Studio Extension For System Z HIGH 10.0
CVE-2013-3712

SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vector…

No fix yet
Fix from $1,950 2014-02-26
Webyast MEDIUM 5.8
CVE-2012-0435

SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a craf…

Mitigation only
Fix from $1,600 2013-01-26
Opensuse HIGH 7.5
CVE-2010-0230

SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers…

Mitigation only
Fix from $1,950 2010-01-22
Suse Linux HIGH 7.5
CVE-2009-1648

The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances invol…

Mitigation only
Fix from $1,950 2009-07-05
Suse Linux HIGH 7.2
CVE-2008-3949

emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which…

Mitigation only
Fix from $1,950 2008-09-22
Suse Linux HIGH 7.2
CVE-2007-6167

Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 modul…

Mitigation only
Fix from $1,950 2007-11-29
Suse Linux HIGH 7.5
CVE-2007-5196

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…

Mitigation only
Fix from $1,950 2007-10-14
Suse Linux MEDIUM 6.4
CVE-2006-2752

The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux Desktop 9 and SUSE SLES 9 has world-readable permissions, which allows attacker…

Mitigation only
Fix from $1,600 2006-06-01
Suse Linux MEDIUM 5.0
CVE-2006-2703

The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows remote attackers to read network traffic and exe…

Mitigation only
Fix from $1,600 2006-06-01
Suse Linux HIGH 7.5
CVE-2005-3298

Multiple buffer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.

No fix yet
Fix from $1,950 2005-10-23
Suse Linux HIGH 7.2
CVE-2002-1285

runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.

Mitigation only
Fix from $1,950 2002-11-29
Suse Linux HIGH 7.2
CVE-2002-0854

Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3, 8.0, and possibly other operating systems, may …

Mitigation only
Fix from $1,950 2002-09-05
Suse Linux HIGH 7.2
CVE-2001-1012

Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under…

Mitigation only
Fix from $1,950 2001-09-05
Suse Linux HIGH 10.0
CVE-2000-0800

String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root pr…

Mitigation only
Fix from $1,950 2000-10-20