← Back

Opensuse

opensuse

3,271 CVEs • 50 products

Products (50)

Click to collapse
Toggle
Leap
leap
Opensuse
opensuse
Backports
backports
Evergreen
evergreen
Libsolv
libsolv
Factory
factory
Supportutils
supportutils
Libzypp
libzypp
Tumbleweed
tumbleweed
Zypper
zypper
Openldap2
openldap2
Osc
osc
Cryptctl
cryptctl
Munge
munge
Wicked
wicked
Pcp
pcp
Rmt Server
rmt-server
Cscreen
cscreen
Libeconf
libeconf
Libstorage
libstorage
Libstorage Ng
libstorage-ng
Sysconfig
sysconfig
Tar Scm
tar_scm
Package Hub
package_hub
Yast2 Printer
yast2-printer
Munin
munin
Autoyast2
autoyast2
Hylafax+
hylafax+
Cyrus Sasl
cyrus-sasl
Inn
inn
Canna
canna
Leap Micro
leap_micro
Paste
paste
Welcome
welcome
Mirrorcache
mirrorcache

CVEs (3,271)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
Flask Cors ProjectOpensuse
4Backports Sle
Debian LinuxFlask Cors+1 more
Nov 21, 2024
Aug 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonica...Show more
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.Show less
3Fedoraproject
OpensuseRedhat
4Backports Sle
FedoraLeap+1 more
Nov 21, 2024
Aug 30, 2020
N/A· v4
8.0 HIGH· v3
8.5 HIGH· v2
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be abl...Show more
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.Show less
3Fedoraproject
Kleopatra ProjectOpensuse
4Backports Sle
FedoraKleopatra+1 more
Nov 21, 2024
Aug 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platfo...Show more
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.Show less
3Fedoraproject
Fossil ScmOpensuse
4Backports Sle
FedoraFossil+1 more
Nov 21, 2024
Aug 25, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Nov 21, 2024
Aug 24, 2020
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer...Show more
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapPostgresql+1 more
Nov 21, 2024
Aug 24, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially cr...Show more
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.Show less
2Opensuse
Postgresql
2Leap
Postgresql
Nov 21, 2024
Aug 24, 2020
N/A· v4
7.1 HIGH· v3
4.6 MEDIUM· v2
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to...Show more
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.Show less
6Canonical
DebianFedoraproject+3 more
6Bind
Debian LinuxFedora+3 more
Nov 21, 2024
Aug 21, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has...Show more
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.Show less
7Canonical
DebianFedoraproject+4 more
7Bind
Debian LinuxDns Server+4 more
Nov 21, 2024
Aug 21, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query p...Show more
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zones with an RSA key * be able to receive queries from a possible attackerShow less
8Canonical
DebianFedoraproject+5 more
8Bind
Communications Diameter Signaling RouterDebian Linux+5 more
Nov 21, 2024
Aug 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the serve...Show more
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.Show less
5Canonical
IscNetapp+2 more
5Bind
Dns ServerLeap+2 more
Nov 21, 2024
Aug 21, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the...Show more
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.Show less
4Canonical
IscNetapp+1 more
4Bind
LeapSteelstore Cloud Integrated Storage+1 more
Nov 21, 2024
Aug 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
6Canonical
DebianLinux+3 more
10Active Iq Unified Manager
Cloud BackupDebian Linux+7 more
Nov 21, 2024
Aug 19, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privile...Show more
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.Show less
5Canonical
LinuxOpensuse+2 more
5Leap
Linux KernelSd Wan Edge+2 more
Nov 21, 2024
Aug 19, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current uma...Show more
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.Show less
8Canonical
DebianFedoraproject+5 more
15Debian Linux
Directory ServerFedora+12 more
Feb 23, 2026
Aug 17, 2020
N/A· v4
10.0 CRITICAL· v3
9.3 HIGH· v2
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successful...Show more
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.Show less
2Opensuse
Ui
3Backports Sle
Edgeswitch FirmwareLeap
Nov 21, 2024
Aug 17, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
4Fedoraproject
OpensuseOracle+1 more
4Fedora
LeapWireshark+1 more
Nov 21, 2024
Aug 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
4Canonical
DebianGnome+1 more
4Debian Linux
Gnome ShellLeap+1 more
Nov 21, 2024
Aug 11, 2020
N/A· v4
4.3 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had dec...Show more
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)Show less
4Debian
FedoraprojectFirejail Project+1 more
4Debian Linux
FedoraFirejail+1 more
Nov 21, 2024
Aug 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
4Debian
FedoraprojectFirejail Project+1 more
4Debian Linux
FedoraFirejail+1 more
Nov 21, 2024
Aug 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.