← Back

Opensuse

opensuse

Vendor: Opensuse • 1,454 CVEs

CVEs (1,454)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one rulesetShow less
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.Show less
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon se...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.Show less
4Debian
OpensuseRedhat+1 more
4Debian Linux
Enterprise LinuxOpensuse+1 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
5Debian
FedoraprojectOpensuse+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
Nov 21, 2024
Nov 13, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
3Dovecot
OpensuseRedhat
4Dovecot
Enterprise LinuxLeap+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
3Debian
HordeOpensuse
3Debian Linux
GroupwareOpensuse
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
5Canonical
DebianIcoutils Project+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafte...Show more
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.Show less
5Canonical
DebianIcoutils Project+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a...Show more
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.Show less
4Canonical
DebianIcoutils Project+1 more
5Debian Linux
IcoutilsLeap+2 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
4Debian
GnomeOpensuse+1 more
4Debian Linux
Enterprise LinuxEvince+1 more
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
evince is missing a check on number of pages which can lead to a segmentation fault
2Mdadm Project
Opensuse
2Mdadm
Opensuse
Nov 21, 2024
Jun 8, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
2Opensuse
Uclouvain
2Openjpeg
Opensuse
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file...Show more
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file because of incorrect j2k_decode, j2k_read_eoc, and tcd_decode_tile interaction, a related issue to CVE-2013-6045. NOTE: this is not a duplicate of CVE-2013-1447, because the scope of CVE-2013-1447 was specifically defined in http://openwall.com/lists/oss-security/2013/12/04/6 as only "null pointer dereferences, division by zero, and anything that would just fit as DoS."Show less
4Debian
LibtiffOpensuse+1 more
5Debian Linux
Enterprise LinuxLeap+2 more
Nov 21, 2024
Mar 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a craft...Show more
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.Show less
5Debian
FedoraprojectOpensuse+2 more
6Debian Linux
FedoraLeap+3 more
May 13, 2026
Dec 5, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
4Opensuse
Opensuse ProjectPython+1 more
4Opensuse
OpensusePython+1 more
May 13, 2026
Aug 24, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the...Show more
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.Show less
2Encfs Project
Opensuse
3Encfs
LeapOpensuse
May 13, 2026
Aug 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
4Fedoraproject
Jasper ProjectOpensuse+1 more
5Fedora
JasperLeap+2 more
May 13, 2026
Aug 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
4Fedoraproject
Jasper ProjectOpensuse+1 more
5Fedora
JasperLeap+2 more
May 13, 2026
Jul 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000...Show more
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.Show less
7Canonical
DebianFedoraproject+4 more
20Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+17 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).Show less