CVEs (208)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
12Amazon AristaCanonical+9 more41Amazon Linux Basesystem ModuleCaas Platform+38 moreMay 21, 2026 Apr 22, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is...Show more |
8Almalinux ArchlinuxGentoo+5 more18Almalinux Arch LinuxEnterprise Linux+15 moreApr 14, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly ena...Show more |
8Almalinux ArchlinuxGentoo+5 more9Almalinux Arch LinuxEnterprise Linux+6 moreMay 26, 2026 Jan 14, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, t...Show more |
8Almalinux ArchlinuxGentoo+5 more22Almalinux Arch LinuxEnterprise Linux+19 moreApr 14, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized...Show more |
3Quagga RedhatSuse4Opensuse Package ManagerQuagga+1 moreNov 21, 2024 Jul 24, 2018 N/A· v4 8.2 HIGH· v3 4.3 MEDIUM· v2 Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same...Show more |
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions. |
The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote at...Show more |
emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute arbitrary code via a Trojan horse Python...Show more |
Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 module in the current working directory. |
libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) v...Show more |
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-mid...Show more |
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-mid...Show more |
Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 allows local users to gain privileges via...Show more |
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via...Show more |
The installation script for orarun on SUSE Linux before 20070810 places the oracle user into the disk group, which allows the local oracle user to read or write raw disk partitions. |
2Centre For Speech Technology Research Suse2Gentoo Linux Suse LinuxApr 23, 2026 Jul 30, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and possibly other distributions, is run locally with elevated privileges without r...Show more |
2Suse Xfsdump7Opensuse Suse LinuxSuse Linux Openexchange Server+4 moreApr 23, 2026 May 14, 2007 N/A· v4 N/A· v3 4.4 MEDIUM· v2 xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems. |
Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations." |
1Suse 3Linux Enterprise Desktop Suse LinuxSuse Open Enterprise ServerApr 23, 2026 Dec 20, 2006 N/A· v4 N/A· v3 4.1 MEDIUM· v2 Unspecified vulnerability in Linux User Management (novell-lum) on SUSE Linux Enterprise Desktop 10 and Open Enterprise Server 9, under unspecified conditions, allows local users to log in to the console without a passwo...Show more |
Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors. |