cbcvebase.

Suse Opensuse vulnerabilities

5 known vulnerabilities affecting suse/opensuse.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-44933P3HIGHCVSS 7.8≥ 17.38.8, < 17.38.92026-05-20
CVE-2026-44933 [HIGH] CWE-35 CVE-2026-44933: `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges.
nvd
CVE-2010-0230P3HIGHCVSS 7.5v11.22010-01-22
CVE-2010-0230 [HIGH] CWE-264 CVE-2010-0230: SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all netwo SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
nvd
CVE-2025-62876P4MEDIUMCVSS 5.3≥ ?, < 6.0.42025-11-12
CVE-2025-62876 [MEDIUM] CWE-250 CVE-2025-62876: A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.
nvd
CVE-2007-2654P4MEDIUMCVSS 4.4v10.22007-05-14
CVE-2007-2654 [MEDIUM] CWE-362 CVE-2007-2654: xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
nvd
CVE-2008-3067P4LOWCVSS 2.1v10.32008-07-07
CVE-2008-3067 [LOW] CWE-255 CVE-2008-3067: sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which migh sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.
nvd
Suse Opensuse vulnerabilities | cvebase