Opensuse
opensuse
3,271 CVEs • 50 products
Products (50)
Click to collapseToggle
Products (50)
Click to collapse
CVEs (3,271)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian Flask Cors ProjectOpensuse4Backports Sle Debian LinuxFlask Cors+1 moreNov 21, 2024 Aug 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonica...Show more |
3Fedoraproject OpensuseRedhat4Backports Sle FedoraLeap+1 moreNov 21, 2024 Aug 30, 2020 N/A· v4 8.0 HIGH· v3 8.5 HIGH· v2 A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be abl...Show more |
3Fedoraproject Kleopatra ProjectOpensuse4Backports Sle FedoraKleopatra+1 moreNov 21, 2024 Aug 29, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platfo...Show more |
3Fedoraproject Fossil ScmOpensuse4Backports Sle FedoraFossil+1 moreNov 21, 2024 Aug 25, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPostgresql+1 moreNov 21, 2024 Aug 24, 2020 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially cr...Show more |
2Opensuse Postgresql2Leap PostgresqlNov 21, 2024 Aug 24, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to...Show more |
6Canonical DebianFedoraproject+3 more6Bind Debian LinuxFedora+3 moreNov 21, 2024 Aug 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has...Show more |
7Canonical DebianFedoraproject+4 more7Bind Debian LinuxDns Server+4 moreNov 21, 2024 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query p...Show more |
8Canonical DebianFedoraproject+5 more8Bind Communications Diameter Signaling RouterDebian Linux+5 moreNov 21, 2024 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the serve...Show more |
5Canonical IscNetapp+2 more5Bind Dns ServerLeap+2 moreNov 21, 2024 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the...Show more |
4Canonical IscNetapp+1 more4Bind LeapSteelstore Cloud Integrated Storage+1 moreNov 21, 2024 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit. |
6Canonical DebianLinux+3 more10Active Iq Unified Manager Cloud BackupDebian Linux+7 moreNov 21, 2024 Aug 19, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privile...Show more |
5Canonical LinuxOpensuse+2 more5Leap Linux KernelSd Wan Edge+2 moreNov 21, 2024 Aug 19, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current uma...Show more |
8Canonical DebianFedoraproject+5 more15Debian Linux Directory ServerFedora+12 moreFeb 23, 2026 Aug 17, 2020 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successful...Show more |
2Opensuse Ui3Backports Sle Edgeswitch FirmwareLeapNov 21, 2024 Aug 17, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges. |
4Fedoraproject OpensuseOracle+1 more4Fedora LeapWireshark+1 moreNov 21, 2024 Aug 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression. |
4Canonical DebianGnome+1 more4Debian Linux Gnome ShellLeap+1 moreNov 21, 2024 Aug 11, 2020 N/A· v4 4.3 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had dec...Show more |
4Debian FedoraprojectFirejail Project+1 more4Debian Linux FedoraFirejail+1 moreNov 21, 2024 Aug 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection. |
4Debian FedoraprojectFirejail Project+1 more4Debian Linux FedoraFirejail+1 moreNov 21, 2024 Aug 11, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection. |