Opensuse

Leap

1897 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Published 10.05.2018 19:29:00
  • Last modified 21.11.2024 03:59:12

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to ...

  • EPSS 0.02%
  • Published 08.05.2018 12:29:00
  • Last modified 21.11.2024 03:41:18

kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.

Exploit
  • EPSS 0.8%
  • Published 04.05.2018 17:29:00
  • Last modified 21.11.2024 03:41:56

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

  • EPSS 5.68%
  • Published 18.04.2018 16:29:00
  • Last modified 21.11.2024 03:59:09

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

  • EPSS 0.07%
  • Published 12.03.2018 21:29:01
  • Last modified 21.11.2024 04:12:53

Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when up...

Exploit
  • EPSS 1.1%
  • Published 12.03.2018 02:29:00
  • Last modified 21.11.2024 02:54:04

Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated...

  • EPSS 1.09%
  • Published 05.03.2018 18:29:00
  • Last modified 21.11.2024 03:19:35

xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.

  • EPSS 0.21%
  • Published 01.03.2018 20:29:01
  • Last modified 21.11.2024 03:35:45

The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.

  • EPSS 0.43%
  • Published 01.03.2018 20:29:00
  • Last modified 21.11.2024 03:13:32

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

Exploit
  • EPSS 0.05%
  • Published 13.02.2018 20:29:00
  • Last modified 09.06.2025 16:15:29

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and la...