← Back

Opensuse

opensuse

3,271 CVEs • 50 products

Products (50)

Click to collapse
Toggle
Leap
leap
Opensuse
opensuse
Backports
backports
Evergreen
evergreen
Libsolv
libsolv
Factory
factory
Supportutils
supportutils
Libzypp
libzypp
Tumbleweed
tumbleweed
Zypper
zypper
Openldap2
openldap2
Osc
osc
Cryptctl
cryptctl
Munge
munge
Wicked
wicked
Pcp
pcp
Rmt Server
rmt-server
Cscreen
cscreen
Libeconf
libeconf
Libstorage
libstorage
Libstorage Ng
libstorage-ng
Sysconfig
sysconfig
Tar Scm
tar_scm
Package Hub
package_hub
Yast2 Printer
yast2-printer
Munin
munin
Autoyast2
autoyast2
Hylafax+
hylafax+
Cyrus Sasl
cyrus-sasl
Inn
inn
Canna
canna
Leap Micro
leap_micro
Paste
paste
Welcome
welcome
Mirrorcache
mirrorcache

CVEs (3,271)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Mariadb
OpensusePcre+1 more
4Mariadb
OpensusePcre+1 more
Nov 21, 2024
Jan 14, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward...Show more
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".Show less
4Mariadb
OpensusePcre+1 more
4Mariadb
OpensusePcre+1 more
Nov 21, 2024
Jan 14, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a...Show more
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.Show less
3Debian
OpensuseSchedmd
3Debian Linux
LeapSlurm
Nov 21, 2024
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
2Opensuse
Schedmd
2Leap
Slurm
Nov 21, 2024
Jan 13, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
5Debian
FedoraprojectGoogle+2 more
7Backports Sle
ChromeDebian Linux+4 more
Nov 21, 2024
Jan 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
4Backports Sle
ChromeDebian Linux+1 more
Nov 21, 2024
Jan 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
3Debian
OpensuseOtrs
4Backports Sle
Debian LinuxLeap+1 more
Nov 21, 2024
Jan 10, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Comm...Show more
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.Show less
5Apple
CanonicalF5+2 more
5Cloud Backup
LeapNginx+2 more
Nov 21, 2024
Jan 9, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a l...Show more
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.Show less
4Freedesktop
OpensuseRedhat+1 more
4Enterprise Linux
OpensusePoppler+1 more
Nov 21, 2024
Jan 9, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
5Canonical
DebianMozilla+2 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.Show less
2Mozilla
Opensuse
3Firefox
Firefox EsrLeap
Nov 21, 2024
Jan 8, 2020
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating s...Show more
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.Show less
3Canonical
MozillaOpensuse
5Firefox
Firefox EsrLeap+2 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.Show less
3Canonical
MozillaOpensuse
5Firefox
Firefox EsrLeap+2 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thund...Show more
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.Show less
3Canonical
MozillaOpensuse
5Firefox
Firefox EsrLeap+2 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability a...Show more
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.Show less
2Mozilla
Opensuse
4Firefox
Firefox EsrLeap+1 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note:...Show more
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.Show less
2Mozilla
Opensuse
4Firefox
Firefox EsrLeap+1 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
3Canonical
MozillaOpensuse
5Firefox
Firefox EsrLeap+2 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable cr...Show more
The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.Show less
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Nov 21, 2024
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Nov 21, 2024
Jan 8, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Nov 21, 2024
Jan 8, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.