Suse
suse
1,152 CVEs • 121 products
Products (121)
Click to collapseToggle
Products (121)
Click to collapse
CVEs (1,152)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Nextcloud OpensuseSuse3Backports Nextcloud ServerSuse Linux Enterprise ServerJun 17, 2026 Feb 4, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. |
3Nextcloud OpensuseSuse3Backports Sle Nextcloud ServerPackage HubJun 17, 2026 Feb 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled. |
3Gnome OpensuseSuse4Linux Enterprise Desktop Linux Enterprise ServerNetworkmanager+1 moreNov 21, 2024 Jan 27, 2020 N/A· v4 6.8 MEDIUM· v3 3.2 LOW· v2 NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used. |
1Suse 2Studio Onsite Susestudio Ui ServerNov 21, 2024 Jan 27, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL sta...Show more |
1Suse 2Studio Onsite Susestudio Ui ServerNov 21, 2024 Jan 27, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these co...Show more |
3Opensuse SuseYast2 Rmt Project3Leap Suse Linux Enterprise ServerYast2 RmtNov 21, 2024 Jan 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affe...Show more |
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user...Show more |
yast2-security didn't use secure defaults to protect passwords. This became a problem on 2019-10-07 when configuration files that set secure settings were moved to a different location. As of the 20191022 snapshot the in...Show more |
A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from user munin to root. This issue affects: openSUSE Factory munin version 2....Show more |
2Opensuse Suse2Backports Sle MailmanJun 17, 2026 Jan 24, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun...Show more |
2Opensuse Suse3Backports Sle InnLeapJun 17, 2026 Jan 24, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn v...Show more |
The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versi...Show more |
5Arista CanonicalFedoraproject+2 more8Eos FedoraLinux Enterprise Debuginfo+5 moreNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. |
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects:...Show more |
openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security |
2Hp Suse3Helion Openstack Keystone Json AssignmentOpenstack CloudJun 17, 2026 Jan 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to...Show more |
The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node. |
5Cacti DebianFedoraproject+2 more7Backports Sle CactiDebian Linux+4 moreJun 17, 2026 Jan 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in dat...Show more |
3Debian PhpmyadminSuse3Debian Linux PhpmyadminSuse Linux Enterprise ServerJun 17, 2026 Jan 9, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker mus...Show more |
2Obs Server Suse2Linux Enterprise Server Obs ServerNov 21, 2024 Jan 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation. |