← Back

Opensuse

opensuse

Vendor: Opensuse • 1,454 CVEs

CVEs (1,454)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
FedoraprojectLinux+3 more
8Fedora
Linux Enterprise DebuginfoLinux Enterprise Desktop+5 more
Apr 23, 2026
Oct 22, 2009
N/A· v4
7.8 HIGH· v3
4.9 MEDIUM· v2
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointe...Show more
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.Show less
6Canonical
FedoraprojectLinux+3 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 23, 2026
Oct 20, 2009
N/A· v4
N/A· v3
2.1 LOW· v2
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier...Show more
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.Show less
5Canonical
FedoraprojectLinux+2 more
7Fedora
Linux Enterprise DesktopLinux Enterprise Server+4 more
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
2.1 LOW· v2
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allo...Show more
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.Show less
3Gnome
OpensuseSuse
3Glib
OpensuseSuse Linux Enterprise Server
Apr 23, 2026
Sep 22, 2009
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Naut...Show more
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.Show less
4Canonical
LinuxOpensuse+1 more
5Linux Enterprise Desktop
Linux Enterprise ServerLinux Kernel+2 more
Apr 23, 2026
Sep 18, 2009
N/A· v4
5.5 MEDIUM· v3
7.8 HIGH· v2
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms...Show more
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."Show less
5Canonical
FedoraprojectOpensuse+2 more
6Fedora
Linux EnterpriseLinux Enterprise Server+3 more
Apr 23, 2026
Sep 17, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
6Apache
AppleDebian+3 more
7Debian Linux
FedoraHttp Server+4 more
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the...Show more
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.Show less
8Canonical
FedoraprojectLinux+5 more
12Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+9 more
Apr 23, 2026
Aug 18, 2009
N/A· v4
N/A· v3
5.9 MEDIUM· v2
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibl...Show more
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.Show less
11Apple
CanonicalDebian+8 more
19Chrome
Debian LinuxEnterprise Linux+16 more
Apr 23, 2026
Aug 11, 2009
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notatio...Show more
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.Show less
7Apache
CanonicalDebian+4 more
9Debian Linux
FedoraJdk+6 more
Apr 23, 2026
Aug 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a deni...Show more
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.Show less
6Apple
CanonicalDebian+3 more
6Debian Linux
FedoraMac Os X+3 more
Apr 23, 2026
Jul 31, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via ve...Show more
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.Show less
5Canonical
DebianMozilla+2 more
9Debian Linux
FirefoxLinux Enterprise+6 more
Apr 23, 2026
Jul 30, 2009
N/A· v4
5.9 MEDIUM· v3
6.8 MEDIUM· v2
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name...Show more
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.Show less
4Fedoraproject
MozillaOpensuse+1 more
6Fedora
FirefoxLinux Enterprise Debuginfo+3 more
Apr 23, 2026
Jul 22, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) atta...Show more
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."Show less
3Apple
CanonicalOpensuse
4Iphone Os
OpensuseSafari+1 more
Apr 23, 2026
Jun 10, 2009
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote atta...Show more
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."Show less
5Apple
CanonicalDebian+2 more
7Cups
Debian LinuxLinux Enterprise+4 more
Apr 23, 2026
Jun 9, 2009
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and da...Show more
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Linux EnterpriseLinux Enterprise Desktop+4 more
Apr 23, 2026
Jun 8, 2009
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a den...Show more
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.Show less
5Canonical
DebianLinux+2 more
5Debian Linux
EsxLinux Kernel+2 more
Apr 23, 2026
May 14, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which a...Show more
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.Show less
2Francis James Franklin
Opensuse
2Libwmf
Opensuse
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.
6Canonical
DebianFedoraproject+3 more
8Debian Linux
FedoraLinux Enterprise Debuginfo+5 more
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
2.1 LOW· v2
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
7Canonical
DebianFedoraproject+4 more
9Ctpview
Debian LinuxFedora+6 more
Apr 23, 2026
Apr 17, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.