← Back

Suse

suse

1,152 CVEs • 121 products

Products (121)

Click to collapse
Toggle
Suse Linux
suse_linux
Package Hub
package_hub
Rancher
rancher
Studio Onsite
studio_onsite
Manager
manager
Manager Proxy
manager_proxy
Caas Platform
caas_platform
Opensuse
opensuse
Webyast
webyast
Kiwi
kiwi
Rancher Fleet
rancher_fleet
Linux
linux
Cloud
cloud
Portus
portus
Backports
backports
Rancher Rke2
rancher_rke2
Wrangler
wrangler
Office Server
office_server
Suse Cvsup
suse_cvsup
Suse Iptables
suse_iptables
Yast2 Backup
yast2-backup
Vpnc
vpnc
Studio
studio
Opensuse Osc
opensuse_osc
Yast2
yast2
Opensuse Leap
opensuse_leap
Susefirewall2
susefirewall2
Shadow
shadow
Openqa
openqa
Trousers
trousers
Inn
inn
Mailman
mailman
Munin
munin
Yast2 Security
yast2-security
S390 Tools
s390-tools

CVEs (1,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
RedhatSuse
4Ansible Engine
Ansible TowerDebian Linux+1 more
Nov 21, 2024
Oct 23, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing...Show more
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.Show less
6Canonical
DebianKyzer+3 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
Nov 21, 2024
Oct 23, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
7Cabextract Project
CanonicalDebian+4 more
7Cabextract
Debian LinuxEnterprise Linux+4 more
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
6Canonical
DebianOracle+3 more
6Debian Linux
LinuxLinux+3 more
Nov 21, 2024
Oct 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
8.1 HIGH· v3
6.4 MEDIUM· v2
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior...Show more
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.Show less
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
1Suse
1Shadow
Nov 21, 2024
Sep 26, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUSE Linux Enterprise 15...Show more
Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUSE Linux Enterprise 15 (SLE-15). Non-existing intermediate directories are created with mode 0777 during user creation. Given that they are world-writable, local attackers might use this for privilege escalation and other unspecified attacks. NOTE: this would affect non-SUSE users who took useradd.c code from a 2014-04-02 upstream pull request; however, no non-SUSE distribution is known to be affected.Show less
2Pidgin
Suse
2Linux Enterprise Server
Pidgin
Nov 21, 2024
Sep 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution...Show more
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.Show less
4Canonical
LinuxcontainersOpensuse+1 more
6Caas Platform
LeapLxc+3 more
Jun 17, 2026
Aug 10, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise...Show more
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.Show less
3Quagga
RedhatSuse
4Opensuse
Package ManagerQuagga+1 more
Nov 21, 2024
Jul 24, 2018
N/A· v4
8.2 HIGH· v3
4.3 MEDIUM· v2
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same...Show more
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge. In a case where the sequence numbers are the same, the LSA with the larger checksum is considered more recent, and will not be flushed from the Link State Database (LSDB). Since the RFC does not explicitly state that the values of links carried by a LSA must be the same when prematurely aging a self-originating LSA with MaxSequenceNumber, it is possible in vulnerable OSPF implementations for an attacker to craft a LSA with MaxSequenceNumber and invalid links that will result in a larger checksum and thus a 'newer' LSA that will not be flushed from the LSDB. Propagation of the crafted LSA can result in the erasure or alteration of the routing tables of routers within the routing domain, creating a denial of service condition or the re-routing of traffic on the network. CVE-2017-3224 has been reserved for Quagga and downstream implementations (SUSE, openSUSE, and Red Hat packages).Show less
3Aubio
OpensuseSuse
3Aubio
LeapLinux Enterprise
Nov 21, 2024
Jul 23, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.
3Aubio
OpensuseSuse
3Aubio
LeapLinux Enterprise
Nov 21, 2024
Jul 23, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.
4Canonical
DebianRedhat+1 more
10Ansible Engine
Ceph StorageDebian Linux+7 more
Nov 21, 2024
Jul 13, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execu...Show more
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.Show less
1Suse
2Suse Linux Enterprise Desktop
Suse Linux Enterprise Server
Nov 21, 2024
Jun 8, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implemen...Show more
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).Show less
1Suse
1Suse Linux Enterprise Server
Nov 21, 2024
Jun 8, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
1Suse
2Studio Onsite
Studio Onsite Appliance
Nov 21, 2024
Jun 7, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE St...Show more
A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE Studio Onsite: versions prior to 1.0.3-0.18.1, SUSE Studio Onsite 1.1 Appliance: versions prior to 1.1.2-0.25.1.Show less
6Canonical
DebianLinux+3 more
12Communications Eagle Application Processor
Debian LinuxEnterprise Linux Desktop+9 more
Jun 17, 2026
Mar 30, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
1Suse
1Portus
Jun 17, 2026
Mar 11, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validation issue because no proxy_ssl_* directive...Show more
The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validation issue because no proxy_ssl_* directives are used.Show less
2Opensuse
Suse
2Leap
Linux Enterprise Software Development Kit
Nov 21, 2024
Mar 1, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.