VendorsSUSElinux_enterprise_high_performance_computingall versions
Vulnerabilities

SUSE Linux Enterprise High Performance Computing 15.0 ESPOS Edition

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2020-8025
outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues
Published 2020-08-07 · Modified
9.3EPSS 0.005
CVE-2019-3695
pcp: Local privilege escalation from user pcp to root
Published 2020-03-03 · Modified
8.4EPSS 0.005
CVE-2019-3696
pcp: Local privilege escalation from user pcp to root through migrate_tempdirs
Published 2020-03-03 · Modified
8.4EPSS 0.005
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Published 2022-01-28 · Analyzed
7.8KEV1 PoCEPSS 0.943
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Published 2026-04-22 · Analyzed
7.8KEVEPSS 0.034
CVE-2022-27239
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Published 2022-04-27 · Modified
7.8EPSS 0.006
CVE-2024-46956
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
Published 2024-11-10 · Modified
7.8EPSS 0.004
CVE-2024-46953
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
Published 2024-11-10 · Modified
7.8EPSS 0.004
CVE-2024-46951
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
Published 2024-11-10 · Modified
7.8EPSS 0.004
CVE-2023-32182
A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1; SUSE Linux Enterprise High Performance Computing 15 SP5: before 3.7.3-150500.3.5.1; openSUSE Leap 15.5 : before 3.7.3-150500.3.5.1.
Published 2023-09-19 · Modified
7.8EPSS 0.003
CVE-2019-18904
Migrations requests can cause DoS on rmt
Published 2020-04-03 · Modified
7.5EPSS 0.016
CVE-2024-46955
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
Published 2024-11-10 · Modified
5.5EPSS 0.003