Suse
suse
1,152 CVEs • 121 products
Products (121)
Click to collapseToggle
Products (121)
Click to collapse
CVEs (1,152)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian RedhatSuse4Ansible Engine Ansible TowerDebian Linux+1 moreNov 21, 2024 Oct 23, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing...Show more |
6Canonical DebianKyzer+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Oct 23, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name). |
7Cabextract Project CanonicalDebian+4 more7Cabextract Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Oct 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write. |
6Canonical DebianOracle+3 more6Debian Linux LinuxLinux+3 moreNov 21, 2024 Oct 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used. |
1Suse 1Subscription Management Tool Nov 21, 2024 Oct 4, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37. |
1Suse 1Subscription Management Tool Nov 21, 2024 Oct 4, 2018 N/A· v4 8.1 HIGH· v3 6.4 MEDIUM· v2 A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior...Show more |
1Suse 1Subscription Management Tool Nov 21, 2024 Oct 4, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37. |
Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUSE Linux Enterprise 15...Show more |
2Pidgin Suse2Linux Enterprise Server PidginNov 21, 2024 Sep 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution...Show more |
4Canonical LinuxcontainersOpensuse+1 more6Caas Platform LeapLxc+3 moreJun 17, 2026 Aug 10, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise...Show more |
3Quagga RedhatSuse4Opensuse Package ManagerQuagga+1 moreNov 21, 2024 Jul 24, 2018 N/A· v4 8.2 HIGH· v3 4.3 MEDIUM· v2 Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same...Show more |
3Aubio OpensuseSuse3Aubio LeapLinux EnterpriseNov 21, 2024 Jul 23, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes. |
3Aubio OpensuseSuse3Aubio LeapLinux EnterpriseNov 21, 2024 Jul 23, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes. |
4Canonical DebianRedhat+1 more10Ansible Engine Ceph StorageDebian Linux+7 moreNov 21, 2024 Jul 13, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execu...Show more |
1Suse 2Suse Linux Enterprise Desktop Suse Linux Enterprise ServerNov 21, 2024 Jun 8, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implemen...Show more |
1Suse 1Suse Linux Enterprise Server Nov 21, 2024 Jun 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12. |
1Suse 2Studio Onsite Studio Onsite ApplianceNov 21, 2024 Jun 7, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE St...Show more |
6Canonical DebianLinux+3 more12Communications Eagle Application Processor Debian LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Mar 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user. |
The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validation issue because no proxy_ssl_* directive...Show more |
2Opensuse Suse2Leap Linux Enterprise Software Development KitNov 21, 2024 Mar 1, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots. |