Suse Studio Extension For System Z vulnerabilities

5 known vulnerabilities affecting suse/studio_extension_for_system_z.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2011-4195HIGHCVSS 7.5v1.22014-04-16
CVE-2011-4195 [HIGH] CVE-2011-4195: kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for Sy kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.
nvd
CVE-2011-4192HIGHCVSS 7.5v1.22014-04-16
CVE-2011-4192 [HIGH] CVE-2011-4192: kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for Sys kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."
nvd
CVE-2011-3180HIGHCVSS 7.5v1.22014-04-16
CVE-2011-3180 [HIGH] CVE-2011-3180: kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for Sy kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.
nvd
CVE-2011-4193MEDIUMCVSS 4.3v1.22014-04-16
CVE-2011-4193 [MEDIUM] CWE-79 CVE-2011-4193: Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1 Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted application, related to cloning.
nvd
CVE-2013-3712CRITICALCVSS 10.0v1.32014-02-26
CVE-2013-3712 [CRITICAL] CWE-310 CVE-2013-3712: SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secre SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.
nvd