← Back

Suse

suse

1,152 CVEs • 121 products

Products (121)

Click to collapse
Toggle
Suse Linux
suse_linux
Package Hub
package_hub
Rancher
rancher
Studio Onsite
studio_onsite
Manager
manager
Manager Proxy
manager_proxy
Caas Platform
caas_platform
Opensuse
opensuse
Webyast
webyast
Kiwi
kiwi
Rancher Fleet
rancher_fleet
Linux
linux
Cloud
cloud
Portus
portus
Backports
backports
Rancher Rke2
rancher_rke2
Wrangler
wrangler
Office Server
office_server
Suse Cvsup
suse_cvsup
Suse Iptables
suse_iptables
Yast2 Backup
yast2-backup
Vpnc
vpnc
Studio
studio
Opensuse Osc
opensuse_osc
Yast2
yast2
Opensuse Leap
opensuse_leap
Susefirewall2
susefirewall2
Shadow
shadow
Openqa
openqa
Trousers
trousers
Inn
inn
Mailman
mailman
Munin
munin
Yast2 Security
yast2-security
S390 Tools
s390-tools

CVEs (1,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Suse
1Opensuse
May 13, 2026
Aug 17, 2017
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
7Debian
FedoraprojectNtp+4 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 more
May 13, 2026
Aug 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and...Show more
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.Show less
7Canonical
DebianFedoraproject+4 more
20Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+17 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).Show less
10Canonical
DebianFedoraproject+7 more
18Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+15 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a craft...Show more
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.Show less
6Canonical
DebianFedoraproject+3 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+10 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
8Debian
GnuMcafee+5 more
20Cloud Magnum Orchestration
Debian LinuxEnterprise Linux+17 more
May 13, 2026
Jun 19, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hard...Show more
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.Show less
2Php
Suse
3Linux Enterprise Module For Web Scripting
Linux Enterprise Software Development KitPhp
May 13, 2026
Jun 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.
3Novell
SuseXen
6Manager
Manager ProxyOpenstack Cloud+3 more
May 13, 2026
May 3, 2017
N/A· v4
3.8 LOW· v3
1.7 LOW· v2
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function....Show more
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraLeap+7 more
May 13, 2026
Apr 13, 2017
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
4Game Music Emu Project
OpensuseOpensuse Project+1 more
9Game Music Emu
LeapLeap+6 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
4Game Music Emu Project
OpensuseOpensuse Project+1 more
9Game Music Emu
LeapLeap+6 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
4Game Music Emu Project
OpensuseOpensuse Project+1 more
9Game Music Emu
LeapLeap+6 more
May 13, 2026
Apr 12, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in game-music-emu before 0.6.1.
2Freeradius
Suse
3Freeradius
Linux Enterprise ServerLinux Enterprise Software Development Kit
May 13, 2026
Apr 5, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
1Suse
1Rancher
May 13, 2026
Mar 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher...Show more
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.Show less
5Clusterlabs
OpensuseOpensuse Project+2 more
7Enterprise Linux High Availability
Enterprise Linux Resilient StorageLeap+4 more
May 13, 2026
Mar 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
4Fedoraproject
Jasper ProjectOpensuse+1 more
6Fedora
JasperLeap+3 more
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
1Suse
3Linux Enterprise Desktop
Linux Enterprise ServerSuse Linux Enterprise Server
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as...Show more
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).Show less
5Canonical
ImagemagickOpensuse+2 more
11Imagemagick
LeapLeap+8 more
May 13, 2026
Mar 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
5Canonical
ImagemagickOpensuse+2 more
11Imagemagick
LeapLeap+8 more
May 13, 2026
Mar 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
5Canonical
ImagemagickOpensuse+2 more
10Imagemagick
LeapOpensuse+7 more
May 13, 2026
Mar 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.