← Back

Opensuse

opensuse

3,271 CVEs • 50 products

Products (50)

Click to collapse
Toggle
Leap
leap
Opensuse
opensuse
Backports
backports
Evergreen
evergreen
Libsolv
libsolv
Factory
factory
Supportutils
supportutils
Libzypp
libzypp
Tumbleweed
tumbleweed
Zypper
zypper
Openldap2
openldap2
Osc
osc
Cryptctl
cryptctl
Munge
munge
Wicked
wicked
Pcp
pcp
Rmt Server
rmt-server
Cscreen
cscreen
Libeconf
libeconf
Libstorage
libstorage
Libstorage Ng
libstorage-ng
Sysconfig
sysconfig
Tar Scm
tar_scm
Package Hub
package_hub
Yast2 Printer
yast2-printer
Munin
munin
Autoyast2
autoyast2
Hylafax+
hylafax+
Cyrus Sasl
cyrus-sasl
Inn
inn
Canna
canna
Leap Micro
leap_micro
Paste
paste
Welcome
welcome
Mirrorcache
mirrorcache

CVEs (3,271)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianIjg+4 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+10 more
Nov 21, 2024
May 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
2Opensuse
Postgresql
2Leap
Postgresql
Nov 21, 2024
May 10, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, a...Show more
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.Show less
3Debian
KdeOpensuse
3Debian Linux
LeapPlasma
Nov 21, 2024
May 8, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
3Gnome
OpensuseRedhat
6Ansible Tower
Enterprise Linux DesktopEnterprise Linux Server+3 more
Nov 21, 2024
May 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
3Debian
OpensuseRedhat
6Debian Linux
Enterprise Linux ServerGluster Storage+3 more
Nov 21, 2024
Apr 18, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious...Show more
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.Show less
2Opensuse
Uclouvain
2Openjpeg
Opensuse
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file...Show more
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file because of incorrect j2k_decode, j2k_read_eoc, and tcd_decode_tile interaction, a related issue to CVE-2013-6045. NOTE: this is not a duplicate of CVE-2013-1447, because the scope of CVE-2013-1447 was specifically defined in http://openwall.com/lists/oss-security/2013/12/04/6 as only "null pointer dereferences, division by zero, and anything that would just fit as DoS."Show less
1Opensuse
1Open Build Service
Nov 21, 2024
Mar 20, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
4Canonical
OpensuseQemu+1 more
9Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+6 more
Jun 17, 2026
Mar 12, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorr...Show more
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.Show less
4Debian
LibtiffOpensuse+1 more
5Debian Linux
Enterprise LinuxLeap+2 more
Nov 21, 2024
Mar 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a craft...Show more
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.Show less
2Opensuse
Xv Project
2Leap
Xv
Nov 21, 2024
Mar 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
1Opensuse
1Open Buildservice
Nov 21, 2024
Mar 2, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to b...Show more
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service.Show less
1Opensuse
1Leap
Nov 21, 2024
Mar 1, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
1Opensuse
1Obs Service Source Validator
Nov 21, 2024
Mar 1, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
2Fedoraproject
Opensuse
2Fedora
Zypper
Nov 21, 2024
Mar 1, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
1Opensuse
1Cryptctl
Nov 21, 2024
Mar 1, 2018
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.
1Opensuse
1Libzypp
Nov 21, 2024
Mar 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
1Opensuse
1Open Build Service
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions l...Show more
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).Show less
1Opensuse
1Libzypp
Nov 21, 2024
Mar 1, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
1Opensuse
1Libzypp
Nov 21, 2024
Mar 1, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
1Opensuse
1Open Build Service
Nov 21, 2024
Mar 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.