Opensuse
opensuse
3,271 CVEs • 50 products
Products (50)
Click to collapseToggle
Products (50)
Click to collapse
CVEs (3,271)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical LinuxOpensuse+1 more5Linux Enterprise Desktop Linux Enterprise ServerLinux Kernel+2 moreApr 23, 2026 Sep 18, 2009 N/A· v4 5.5 MEDIUM· v3 7.8 HIGH· v2 The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms...Show more |
5Canonical FedoraprojectOpensuse+2 more6Fedora Linux EnterpriseLinux Enterprise Server+3 moreApr 23, 2026 Sep 17, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. |
6Apache AppleDebian+3 more7Debian Linux FedoraHttp Server+4 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the...Show more |
8Canonical FedoraprojectLinux+5 more12Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+9 moreApr 23, 2026 Aug 18, 2009 N/A· v4 N/A· v3 5.9 MEDIUM· v2 The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibl...Show more |
11Apple CanonicalDebian+8 more19Chrome Debian LinuxEnterprise Linux+16 moreApr 23, 2026 Aug 11, 2009 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notatio...Show more |
7Apache CanonicalDebian+4 more9Debian Linux FedoraJdk+6 moreApr 23, 2026 Aug 6, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a deni...Show more |
6Apple CanonicalDebian+3 more6Debian Linux FedoraMac Os X+3 moreApr 23, 2026 Jul 31, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via ve...Show more |
5Canonical DebianMozilla+2 more9Debian Linux FirefoxLinux Enterprise+6 moreApr 23, 2026 Jul 30, 2009 N/A· v4 5.9 MEDIUM· v3 6.8 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name...Show more |
4Fedoraproject MozillaOpensuse+1 more6Fedora FirefoxLinux Enterprise Debuginfo+3 moreApr 23, 2026 Jul 22, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) atta...Show more |
3Apple CanonicalOpensuse4Iphone Os OpensuseSafari+1 moreApr 23, 2026 Jun 10, 2009 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote atta...Show more |
5Apple CanonicalDebian+2 more7Cups Debian LinuxLinux Enterprise+4 moreApr 23, 2026 Jun 9, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and da...Show more |
5Canonical DebianLinux+2 more7Debian Linux Linux EnterpriseLinux Enterprise Desktop+4 moreApr 23, 2026 Jun 8, 2009 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a den...Show more |
5Canonical DebianLinux+2 more5Debian Linux EsxLinux Kernel+2 moreApr 23, 2026 May 14, 2009 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which a...Show more |
2Francis James Franklin Opensuse2Libwmf OpensuseApr 23, 2026 May 1, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file. |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraLinux Enterprise Debuginfo+5 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments. |
7Canonical DebianFedoraproject+4 more9Ctpview Debian LinuxFedora+6 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. |
6Apple CanonicalDebian+3 more9Debian Linux FreetypeIphone Os+6 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cff...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLinux Kernel+2 moreApr 23, 2026 Apr 6, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting...Show more |
8Avaya Christophe.varoquiDebian+5 more11Ctpview Debian LinuxFedora+8 moreApr 23, 2026 Mar 30, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writab...Show more |
6Canonical DebianLinux+3 more11Debian Linux EsxLinux Enterprise Desktop+8 moreApr 23, 2026 Mar 25, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been e...Show more |