Vulnerability index

Browse CVEs

159 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libzypp HIGH 8.8
CVE-2026-44941

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a maliciou…

Fix: 17.38.12+
Fix from $1,950 2026-07-02
Libzypp HIGH 8.8
CVE-2026-25707

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repo…

Fix: 17.38.10+
Fix from $1,950 2026-06-29
Mirrorcache MEDIUM 6.1
CVE-2024-49505

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the ex…

Fix: 1.083+
Fix from $1,600 2024-11-13
Leap HIGH 7.8
CVE-2023-32182

A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux …

No fix yet
Fix from $1,950 2023-09-19
Welcome HIGH 7.8
CVE-2023-32184

A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs o…

Fix: 0.1.9+
Fix from $1,950 2023-09-19
Tumbleweed HIGH 7.8
CVE-2023-32183

Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root Th…

No fix yet
Fix from $1,950 2023-07-07
Libeconf MEDIUM 6.5
CVE-2023-22652

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. …

Fix: 0.5.2+
Fix from $1,600 2023-06-01
Libeconf MEDIUM 6.5
CVE-2023-32181

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuratio…

Fix: 0.5.2+
Fix from $1,600 2023-06-01
Supportutils MEDIUM 5.5
CVE-2022-45154

A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE…

Fix: after 3.1.21-150300.7.35.15.1
Fix from $1,600 2023-02-15
Paste MEDIUM 6.1
CVE-2022-21948

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javas…

Fix: 2011-12-05+
Fix from $1,600 2023-02-07
Rmt Server HIGH 7.8
CVE-2022-31254

A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Serv…

Fix: 2.10+
Fix from $1,950 2023-02-07
Libzypp Plugin Appdata HIGH 7.8
CVE-2023-22643

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux E…

Fix: 1.0.1+
Fix from $1,950 2023-02-07
Travel Support Program HIGH 7.5
CVE-2022-46163

Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Ha…

Fix: 2022-11-29+
Fix from $1,950 2023-01-10
Openldap2 HIGH 7.8
CVE-2022-31253

A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change owners…

Fix: 2.6.3-404.1+
Fix from $1,950 2022-11-09
Factory HIGH 7.8
CVE-2022-31256

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory…

Fix: 8.17.1-1.1+
Fix from $1,950 2022-10-26
Factory MEDIUM 6.3
CVE-2022-31251

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over th…

Fix: 22.05.2-3.3+
Fix from $1,600 2022-09-07
Canna MEDIUM 5.3
CVE-2022-21950

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local u…

Fix: 3.7p3-bp153.2.3.1 / 3.7p3-bp154.3.3.1+
Fix from $1,600 2022-09-07
Tumbleweed HIGH 7.8
CVE-2022-31250

A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to …

Fix: 6.4.2-1.1+
Fix from $1,950 2022-07-20
Open Build Service HIGH 8.8
CVE-2022-21949

A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entiti…

Fix: 2.10.13+
Fix from $1,950 2022-05-03
Cscreen MEDIUM 6.1
CVE-2022-21945

A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-defau…

Fix: after 1.3
Fix from $1,600 2022-03-16
Cscreen MEDIUM 5.3
CVE-2022-21946

A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local us…

Fix: after 1.3
Fix from $1,600 2022-03-16
Open Build Service HIGH 8.8
CVE-2021-36777

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present use…

Fix: 2021-10-08+
Fix from $1,950 2022-03-09
Libsolv MEDIUM 6.5
CVE-2021-44568

Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies func…

Fix: 0.7.17+
Fix from $1,600 2022-02-21
Factory Watchman HIGH 7.8
CVE-2022-21944

A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows loca…

Fix: after 4.9.1
Fix from $1,950 2022-01-26
Libsolv HIGH 7.5
CVE-2021-33928

Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

Fix: after 0.7.17
Fix from $1,950 2021-09-02
Libsolv HIGH 7.5
CVE-2021-33929

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

Fix: after 0.7.17
Fix from $1,950 2021-09-02
Libsolv HIGH 7.5
CVE-2021-33930

Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of …

Fix: after 0.7.17
Fix from $1,950 2021-09-02
Libsolv HIGH 7.5
CVE-2021-33938

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

Fix: after 0.7.17
Fix from $1,950 2021-09-02
Cryptctl CRITICAL 9.8
CVE-2019-18906

A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with acc…

Fix: 2.4+
Fix from $2,300 2021-06-30
Python Postorius HIGH 7.8
CVE-2021-31997

A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from use…

Fix: 1.3.2-lp152.1.2+
Fix from $1,950 2021-06-10