Vulnerabilities > Opensuse

DATE CVE VULNERABILITY TITLE RISK
2018-03-20 CVE-2011-3178 Code Injection vulnerability in Opensuse Open Build Service
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
network
low complexity
opensuse CWE-94
8.8
2018-03-12 CVE-2018-7858 Out-of-bounds Read vulnerability in multiple products
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
local
low complexity
qemu opensuse redhat canonical CWE-125
5.5
2018-03-12 CVE-2016-5314 Out-of-bounds Write vulnerability in multiple products
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.
network
low complexity
libtiff opensuse redhat debian CWE-787
8.8
2018-03-05 CVE-2017-18215 Out-of-bounds Write vulnerability in multiple products
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
network
low complexity
xv-project opensuse CWE-787
critical
9.8
2018-03-02 CVE-2015-0796 Link Following vulnerability in Opensuse Open Buildservice
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service.
local
low complexity
opensuse CWE-59
7.8
2018-03-01 CVE-2017-9286 Unspecified vulnerability in Opensuse Leap 42.3
The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
network
low complexity
opensuse
8.8
2018-03-01 CVE-2017-9274 OS Command Injection vulnerability in Opensuse Obs-Service-Source Validator
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
local
low complexity
opensuse CWE-78
7.8
2018-03-01 CVE-2017-9271 Information Exposure Through Log Files vulnerability in multiple products
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
local
low complexity
opensuse fedoraproject CWE-532
3.3
2018-03-01 CVE-2017-9270 Improper Input Validation vulnerability in Opensuse Cryptctl 2.0
In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.
network
low complexity
opensuse CWE-20
critical
9.1
2018-03-01 CVE-2017-9269 Improper Input Validation vulnerability in Opensuse Libzypp
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
network
low complexity
opensuse CWE-20
critical
9.8