Opensuse
opensuse
3,271 CVEs • 50 products
Products (50)
Click to collapseToggle
Products (50)
Click to collapse
CVEs (3,271)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Opensuse Sylabs2Leap SingularityNov 21, 2024 Sep 16, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution. |
4Debian FedoraprojectOpensuse+1 more4Database Interface Debian LinuxFedora+1 moreNov 21, 2024 Sep 16, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integ...Show more |
5Canonical DebianFedoraproject+2 more5Database Interface Debian LinuxFedora+2 moreNov 21, 2024 Sep 16, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. |
4Debian FedoraprojectLinux+1 more4Debian Linux FedoraLeap+1 moreNov 21, 2024 Sep 16, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integ...Show more |
6Canonical DebianFedoraproject+3 more10.net .net CoreBrotli+7 moreNov 21, 2024 Sep 15, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over...Show more |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelNov 21, 2024 Sep 13, 2020 N/A· v4 4.1 MEDIUM· v3 1.9 LOW· v2 The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block de...Show more |
3Atftp Project DebianOpensuse3Atftp Debian LinuxLeapNov 21, 2024 Sep 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denia...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Sep 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack ex...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreNov 21, 2024 Sep 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead...Show more |
3Fedoraproject OpensuseSamba3Cifs Utils FedoraLeapNov 21, 2024 Sep 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as v...Show more |
4Debian OpensuseOracle+1 more5Communications Cloud Native Core Network Function Cloud Native Environment Communications Cloud Native Core PolicyDebian Linux+2 moreNov 21, 2024 Sep 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/...Show more |
4Canonical FedoraprojectGnu+1 more4Fedora GnutlsLeap+1 moreNov 21, 2024 Sep 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs...Show more |
6Debian FedoraprojectNetapp+3 more18Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+15 moreNov 21, 2024 Sep 4, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. |
5Canonical DebianFedoraproject+2 more5Ark Debian LinuxFedora+2 moreNov 21, 2024 Sep 2, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. |
4Fedoraproject GolangOpensuse+1 more4Communications Cloud Native Core Policy FedoraGo+1 moreNov 21, 2024 Sep 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUS...Show more |
1Opensuse 1Open Build Service Nov 21, 2024 Sep 1, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks a...Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux Enterprise LinuxFedora+4 moreNov 21, 2024 Aug 31, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[409...Show more |