Opensuse Factory vulnerabilities
26 known vulnerabilities affecting opensuse/factory.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM4LOW2
Vulnerabilities
Page 1 of 2
CVE-2019-18903P3CRITICALCVSS 9.8≥ wicked, < 0.6.622020-03-02
CVE-2019-18903 [CRITICAL] CWE-416 CVE-2019-18903: A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise S
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions pri
nvd
CVE-2019-18902P3CRITICALCVSS 9.8≥ wicked, < 0.6.622020-03-02
CVE-2019-18902 [CRITICAL] CWE-416 CVE-2019-18902: A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise S
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prio
nvd
CVE-2021-25321P3HIGHCVSS 7.8≥ arpwatch, ≤ 2.1a15-169.52021-06-30
CVE-2021-25321 [HIGH] CWE-61 CVE-2021-25321: A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 1
A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Li
nvd
CVE-2018-12476P3HIGHCVSS 7.5≥ obs-service-tar_scm, < 0.9.2.1537788075.fefaa742020-01-27
CVE-2018-12476 [HIGH] CWE-23 CVE-2018-12476: Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; ope
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUSE Linux Enterprise Server 15 obs-service-tar_scm versions prior to 0.9.2.1
nvd
CVE-2019-3691P3HIGHCVSS 7.8≥ munge, < 0.5.13-6.12020-01-23
CVE-2019-3691 [HIGH] CWE-59 CVE-2019-3691: A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise
A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.
nvd
CVE-2019-3692P3HIGHCVSS 7.8≥ inn, ≤ 2.6.2-2.22020-01-24
CVE-2019-3692 [HIGH] CWE-59 CVE-2019-3692: The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local at
The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.
nvd
CVE-2021-25322P3HIGHCVSS 7.8≥ python-HyperKitty, < 1.3.4-5.12021-06-10
CVE-2021-25322 [HIGH] CWE-61 CVE-2021-25322: A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, F
A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions. openSUSE Factory python-HyperKitty versions
nvd
CVE-2019-18898P3HIGHCVSS 7.8≥ trousers, < 0.3.14-7.12020-01-23
CVE-2019-18898 [HIGH] CWE-59 CVE-2019-18898: UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterpris
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
nvd
CVE-2019-18897P3HIGHCVSS 7.8≥ salt-master, ≤ 2019.2.2-3.12020-03-02
CVE-2019-18897 [HIGH] CWE-59 CVE-2019-18897: A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterp
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linu
nvd
CVE-2022-31253P3HIGHCVSS 7.8≥ openldap2, < 2.6.3-404.12022-11-09
CVE-2022-31253 [HIGH] CWE-426 CVE-2022-31253: A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with c
A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1.
nvd
CVE-2022-21944P3HIGHCVSS 7.8≥ watchman, < 4.9.0-9.12022-01-26
CVE-2022-21944 [HIGH] CWE-59 CVE-2022-21944: A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of o
A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1.
nvd
CVE-2021-31997P3HIGHCVSS 7.8≥ python-postorius, ≤ 1.3.4-2.12021-06-10
CVE-2021-31997 [HIGH] CWE-59 CVE-2021-31997: A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Fa
A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory python-postorius version 1.3.4-2.1 and prior ve
nvd
CVE-2019-3694P3HIGHCVSS 7.8≥ munin, ≤ 2.0.49-4.22020-01-24
CVE-2019-3694 [HIGH] CWE-59 CVE-2019-3694: A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Lea
A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from user munin to root. This issue affects: openSUSE Factory munin version 2.0.49-4.2 and prior versions. openSUSE Leap 15.1 munin version 2.0.40-lp151.1.1 and prior versions.
nvd
CVE-2019-3699P3HIGHCVSS 7.8≥ privoxy, ≤ 3.0.28-2.12020-01-24
CVE-2019-3699 [HIGH] CWE-59 CVE-2019-3699: UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.
nvd
CVE-2021-25319P3HIGHCVSS 7.8≤ 6.1.20-1.1≥ virtualbox, ≤ 6.1.20-1.12021-05-05
CVE-2021-25319 [HIGH] CWE-276 CVE-2021-25319: A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory all
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
nvd
CVE-2022-31256P3HIGHCVSS 7.8fixed in 8.17.1-1.12022-10-26
CVE-2022-31256 [HIGH] CWE-59 CVE-2022-31256: A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by
A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.
nvd
CVE-2020-8015P3HIGHCVSS 7.8≥ exim, < 4.93.0.4-3.12020-04-02
CVE-2020-8015 [HIGH] CWE-59 CVE-2020-8015: A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1.
nvd
CVE-2021-32000P4HIGHCVSS 7.1≥ clone-master-clean-up, ≤ 1.6-1.42021-07-28
CVE-2021-32000 [HIGH] CWE-59 CVE-2021-32000: A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clo
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up version 1.6-4
nvd
CVE-2019-3698P4HIGHCVSS 7.0≥ nagios, ≤ 4.4.5-2.12020-02-28
CVE-2019-3698 [HIGH] CWE-59 CVE-2019-3698: UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linu
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prio
nvd
CVE-2020-8032P4HIGHCVSS 7.0≥ cyrus-sasl, ≤ 2.1.27-4.22021-02-25
CVE-2020-8032 [HIGH] CWE-377 CVE-2020-8032: A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows lo
A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.
nvd
1 / 2Next →