← Back

Opensuse

opensuse

3,271 CVEs • 50 products

Products (50)

Click to collapse
Toggle
Leap
leap
Opensuse
opensuse
Backports
backports
Evergreen
evergreen
Libsolv
libsolv
Factory
factory
Supportutils
supportutils
Libzypp
libzypp
Tumbleweed
tumbleweed
Zypper
zypper
Openldap2
openldap2
Osc
osc
Cryptctl
cryptctl
Munge
munge
Wicked
wicked
Pcp
pcp
Rmt Server
rmt-server
Cscreen
cscreen
Libeconf
libeconf
Libstorage
libstorage
Libstorage Ng
libstorage-ng
Sysconfig
sysconfig
Tar Scm
tar_scm
Package Hub
package_hub
Yast2 Printer
yast2-printer
Munin
munin
Autoyast2
autoyast2
Hylafax+
hylafax+
Cyrus Sasl
cyrus-sasl
Inn
inn
Canna
canna
Leap Micro
leap_micro
Paste
paste
Welcome
welcome
Mirrorcache
mirrorcache

CVEs (3,271)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range...Show more
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
OpensuseUbuntu Linux+1 more
May 6, 2026
Apr 19, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
5Canonical
FedoraprojectGnu+2 more
9Fedora
GlibcLinux Enterprise Debuginfo+6 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.Show less
2Libtiff
Opensuse
2Libtiff
Opensuse
May 6, 2026
Apr 19, 2016
N/A· v4
6.2 MEDIUM· v3
5.0 MEDIUM· v2
Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
3Libav
OpensuseUbuntu
3Leap
LibavUbuntu
May 6, 2026
Apr 19, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.
1Opensuse
2Leap
Opensuse
May 6, 2026
Apr 18, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows local users to obtain sensitive information by reading files in the directo...Show more
The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows local users to obtain sensitive information by reading files in the directory.Show less
1Opensuse
1Opensuse
May 6, 2026
Apr 18, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted BMP file.
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
4Debian
GoogleNovell+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive infor...Show more
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.Show less
4Debian
GoogleNovell+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attack...Show more
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.Show less
3Google
OpensuseSuse
3Chrome
LeapLinux Enterprise
May 6, 2026
Apr 18, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifie...Show more
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extension.Show less
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via cr...Show more
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.Show less
4Debian
GoogleOpensuse+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to...Show more
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."Show less
4Debian
GoogleOpensuse+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive i...Show more
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted JPEG 2000 data in a PDF document.Show less
2Cacti
Opensuse
3Cacti
LeapOpensuse
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
4Debian
FedoraprojectLibssh2+1 more
4Debian Linux
FedoraLibssh2+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecif...Show more
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."Show less