← Back

Opensuse

opensuse

Vendor: Opensuse • 1,454 CVEs

CVEs (1,454)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Opensuse
Opensuse ProjectRedhat+1 more
6Cloudforms
Enterprise LinuxOpensuse+3 more
Apr 29, 2026
Feb 20, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject...Show more
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.Show less
2Opensuse
Standards Based Linux Instrumentation Project
2Opensuse
Standards Based Linux Common Information Model Client
Apr 29, 2026
Feb 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting...Show more
internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML file.Show less
4Armin Burgmeier
OpensuseOpensuse Project+1 more
4Net6
OpensuseOpensuse+1 more
Apr 29, 2026
Feb 10, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occu...Show more
Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.Show less
3Armin Burgmeier
OpensuseOracle
3Net6
OpensuseSolaris
Apr 29, 2026
Feb 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage p...Show more
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.Show less
3Fedoraproject
OpensusePython Bugzilla Project
3Fedora
OpensusePython Bugzilla
Apr 29, 2026
Feb 8, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
2Linux
Opensuse
2Linux Kernel
Opensuse
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer paramete...Show more
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.Show less
5Canonical
DebianOpensuse+2 more
6Debian Linux
LeapLibyaml+3 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code vi...Show more
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.Show less
1Opensuse
2Opensuse
Osc
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
2Gnu
Opensuse
2Cpio
Opensuse
Apr 29, 2026
Feb 6, 2014
N/A· v4
7.2 HIGH· v3
5.0 MEDIUM· v2
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
7Canonical
DebianFedoraproject+4 more
13Debian Linux
Enterprise Manager Ops CenterFedora+10 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict...Show more
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.Show less
7Canonical
DebianFedoraproject+4 more
13Debian Linux
Enterprise Manager Ops CenterFedora+10 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products,...Show more
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.Show less
6Canonical
MozillaOpensuse+3 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web s...Show more
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.Show less
5Canonical
MozillaOpensuse+2 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-t...Show more
The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.Show less
7Canonical
DebianFedoraproject+4 more
17Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+14 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitiv...Show more
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.Show less
7Canonical
DebianFedoraproject+4 more
16Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+13 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary c...Show more
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.Show less
5Canonical
MozillaOpensuse+2 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow...Show more
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.Show less
5Mozilla
OpensuseOpensuse Project+2 more
7Firefox
Linux Enterprise DesktopLinux Enterprise Server+4 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.
5Canonical
MozillaOpensuse+2 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements in...Show more
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.Show less
7Canonical
DebianFedoraproject+4 more
17Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+14 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitra...Show more
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.Show less
7Canonical
DebianFedoraproject+4 more
17Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+14 more
Apr 29, 2026
Feb 6, 2014
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native...Show more
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.Show less