Opensuse Factory vulnerabilities
26 known vulnerabilities affecting opensuse/factory.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM4LOW2
Vulnerabilities
Page 2 of 2
CVE-2022-31251P4MEDIUMCVSS 6.3fixed in 22.05.2-3.32022-09-07
CVE-2022-31251 [MEDIUM] CWE-276 CVE-2022-31251: A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Fa
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.
nvd
CVE-2022-21946P4MEDIUMCVSS 5.3≥ cscreen, ≤ 1.2-1.32022-03-16
CVE-2022-21946 [MEDIUM] CWE-732 CVE-2022-21946: A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration i
A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.
nvd
CVE-2022-21945P4MEDIUMCVSS 6.1≥ cscreen, ≤ 1.2-1.32022-03-16
CVE-2022-21945 [MEDIUM] CWE-377 CVE-2022-21945: A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cau
A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.
nvd
CVE-2021-36781P4MEDIUMCVSS 4.4fixed in 0.8.1-1.1≥ parsec, < 0.8.1-1.12022-01-14
CVE-2021-36781 [MEDIUM] CWE-276 CVE-2021-36781: A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.
nvd
CVE-2021-25317P4LOWCVSS 3.3≥ cups, ≤ 2.3.3op2-2.12021-05-05
CVE-2021-25317 [LOW] CWE-276 CVE-2021-25317: A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Serv
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affe
nvd
CVE-2019-3700P4LOWCVSS 3.3≥ yast2-security, < 4.2.62020-01-24
CVE-2019-3700 [LOW] CWE-327 CVE-2019-3700: yast2-security didn't use secure defaults to protect passwords. This became a problem on 2019-10-07
yast2-security didn't use secure defaults to protect passwords. This became a problem on 2019-10-07 when configuration files that set secure settings were moved to a different location. As of the 20191022 snapshot the insecure default settings were used until yast2-security switched to stronger defaults in 4.2.6 and used the new configuration file locatio
nvd
← Previous2 / 2