Suse
suse
1,152 CVEs • 121 products
Products (121)
Click to collapseToggle
Products (121)
Click to collapse
CVEs (1,152)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cau...Show more |
Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm...Show more |
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fle...Show more |
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affect...Show more |
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2. |
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10. |
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storag...Show more |
12Amazon AristaCanonical+9 more45Amazon Linux Basesystem ModuleCaas Platform+42 moreJul 15, 2026 Apr 22, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is...Show more |
A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise...Show more |
1Suse 1Rancher Backup And Restore Operator Jun 17, 2026 Mar 4, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. |
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the...Show more |
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via S...Show more |
6Canonical DebianOpensuse+3 more8Debian Linux Enterprise LinuxLeap+5 moreJun 17, 2026 Jun 30, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
8Almalinux ArchlinuxGentoo+5 more18Almalinux Arch LinuxEnterprise Linux+15 moreJun 30, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly ena...Show more |
8Almalinux ArchlinuxGentoo+5 more9Almalinux Arch LinuxEnterprise Linux+6 moreJun 30, 2026 Jan 14, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, t...Show more |
8Almalinux ArchlinuxGentoo+5 more22Almalinux Arch LinuxEnterprise Linux+19 moreJul 20, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized...Show more |
3Artifex DebianSuse5Debian Linux GhostscriptLinux Enterprise High Performance Computing+2 moreJun 17, 2026 Nov 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution. |
3Artifex DebianSuse5Debian Linux GhostscriptLinux Enterprise High Performance Computing+2 moreJun 17, 2026 Nov 10, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space. |
3Artifex DebianSuse5Debian Linux GhostscriptLinux Enterprise High Performance Computing+2 moreJun 17, 2026 Nov 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traver...Show more |
3Artifex DebianSuse5Debian Linux GhostscriptLinux Enterprise High Performance Computing+2 moreJun 17, 2026 Nov 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution. |