VendorsopenSUSEfactoryall versions
Vulnerabilities

openSUSE Factory

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2019-3681
osc: stores downloaded (supposed) RPM in network-controlled filesystem paths
Published 2020-06-29 · Modified
9.8EPSS 0.014
CVE-2019-3691
Local privilege escalation from user munge to root
Published 2020-01-23 · Modified
7.8EPSS 0.005
CVE-2019-3692
Local privilege escalation from user news to root in the packaging of inn
Published 2020-01-24 · Modified
7.8EPSS 0.005
CVE-2021-45082
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
Published 2022-02-18 · Modified
7.8EPSS 0.005
CVE-2021-25321
arpwatch: Local privilege escalation from runtime user to root
Published 2021-06-30 · Modified
7.8EPSS 0.004
CVE-2021-25322
python-HyperKitty: hyperkitty-permissions.sh used during %post allows local privilege escalation from hyperkitty user to root
Published 2021-06-10 · Modified
7.8EPSS 0.004
CVE-2019-3694
Local privilege escalation from munin to root in the packaging of munin
Published 2020-01-24 · Modified
7.8EPSS 0.004
CVE-2019-3699
Local privilege escalation from user privoxy to root
Published 2020-01-24 · Modified
7.8EPSS 0.004
CVE-2021-31997
python-postorius: postorius-permissions.sh used during %post allows local privilege escalation from postorius user to root
Published 2021-06-10 · Modified
7.8EPSS 0.003
CVE-2021-25319
virtualbox: missing sticky bit for /etc/vbox allows local root exploit for members of vboxusers group
Published 2021-05-05 · Modified
7.8EPSS 0.003
CVE-2022-31256
sendmail: mail to root privilege escalation via sm-client.pre script
Published 2022-10-26 · Modified
7.8EPSS 0.002
CVE-2021-41817
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Published 2022-01-01 · Modified
7.5EPSS 0.032
CVE-2021-41819
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
Published 2022-01-01 · Modified
7.5EPSS 0.029
CVE-2021-4166
Out-of-bounds Read in vim/vim
Published 2021-12-25 · Modified
7.1EPSS 0.016
CVE-2022-31251
slurm: %post for slurm-testsuite operates as root in user owned directory
Published 2022-09-07 · Modified
6.5EPSS 0.002
CVE-2022-21945
cscreen: usage of fixed path /tmp/cscreen.debug
Published 2022-03-16 · Modified
6.1EPSS 0.002
CVE-2021-36781
parsec: dangerous 777 permissions for /run/parsec
Published 2022-01-14 · Modified
5.9EPSS 0.002
CVE-2021-46141
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
Published 2022-01-06 · Modified
5.5EPSS 0.011
CVE-2021-46142
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
Published 2022-01-06 · Modified
5.5EPSS 0.011
CVE-2022-21946
suddoers configuration for cscreen not restrictive enough
Published 2022-03-16 · Modified
5.3EPSS 0.003
CVE-2022-21950
canna: unsafe handling of /tmp/.iroha_unix directory
Published 2022-09-07 · Modified
5.3EPSS 0.002
CVE-2021-46705
grub2-once uses fixed file name in /var/tmp
Published 2022-03-16 · Modified
5.1EPSS 0.002
CVE-2021-25317
cups: ownership of /var/log/cups allows the lp user to create files as root
Published 2021-05-05 · Modified
3.3EPSS 0.003