CVE-2025-32463
- EPSS 23.61%
- Published 30.06.2025 00:00:00
- Last modified 30.09.2025 13:30:30
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2023-32182
- EPSS 0.02%
- Published 19.09.2023 16:15:09
- Last modified 21.11.2024 08:02:51
A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affe...
CVE-2022-45153
- EPSS 0.05%
- Published 15.02.2023 10:15:16
- Last modified 21.11.2024 07:28:51
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by mani...
CVE-2022-31252
- EPSS 0.03%
- Published 06.10.2022 18:16:01
- Last modified 21.11.2024 07:04:13
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a grou...
CVE-2021-46141
- EPSS 0.09%
- Published 06.01.2022 04:15:06
- Last modified 21.11.2024 06:33:40
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
CVE-2021-46142
- EPSS 0.09%
- Published 06.01.2022 04:15:06
- Last modified 21.11.2024 06:33:40
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
CVE-2021-41819
- EPSS 0.88%
- Published 01.01.2022 06:15:07
- Last modified 22.05.2025 15:15:54
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
CVE-2021-41817
- EPSS 0.54%
- Published 01.01.2022 05:15:08
- Last modified 21.11.2024 06:26:48
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
CVE-2021-26675
- EPSS 0.14%
- Published 09.02.2021 16:15:12
- Last modified 21.11.2024 05:56:39
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
CVE-2021-26676
- EPSS 0.1%
- Published 09.02.2021 16:15:12
- Last modified 21.11.2024 05:56:39
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.