VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Opensuse
> Leap
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2023-09-19
CVE-2023-32182
A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1; SUSE Linux Enterprise High Performance Computing 15 SP5: before 3.7.3-150500.3.5.1; openSUSE Leap 15.5 : before 3.7.3-150500.3.5.1.
local
low complexity
opensuse
suse
7.8
7.8
2023-02-15
CVE-2022-45153
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created.
local
low complexity
suse
opensuse
7.8
7.8
2022-10-06
CVE-2022-31252
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged binary to influence path resolution.
local
low complexity
suse
opensuse
4.4
4.4
2022-01-06
CVE-2021-46141
Use After Free vulnerability in multiple products
An issue was discovered in uriparser before 0.9.6.
local
low complexity
uriparser-project
fedoraproject
debian
opensuse
CWE-416
5.5
5.5
2022-01-06
CVE-2021-46142
Use After Free vulnerability in multiple products
An issue was discovered in uriparser before 0.9.6.
local
low complexity
uriparser-project
fedoraproject
debian
opensuse
CWE-416
5.5
5.5
2022-01-01
CVE-2021-41819
Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names.
network
low complexity
ruby-lang
redhat
debian
suse
opensuse
fedoraproject
CWE-565
7.5
7.5
2022-01-01
CVE-2021-41817
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string.
network
low complexity
ruby-lang
redhat
fedoraproject
debian
suse
opensuse
7.5
7.5
2021-02-09
CVE-2021-26676
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
low complexity
intel
debian
opensuse
6.5
6.5
2021-02-09
CVE-2021-26675
Out-of-bounds Write vulnerability in multiple products
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
low complexity
intel
debian
opensuse
CWE-787
8.8
8.8
2020-11-23
CVE-2020-0569
Out-of-bounds Write vulnerability in multiple products
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
low complexity
intel
debian
canonical
opensuse
qt
CWE-787
5.7
5.7
«
1
(current)
2
3
4
5
...
180
181
»
Next