Opensuse

Factory

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 26.10.2022 09:15:15
  • Last modified 21.11.2024 07:04:14

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory...

Exploit
  • EPSS 0.03%
  • Published 07.09.2022 09:15:08
  • Last modified 21.11.2024 07:04:13

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05....

Exploit
  • EPSS 0.04%
  • Published 19.02.2022 00:15:17
  • Last modified 21.11.2024 06:31:54

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

Exploit
  • EPSS 0.09%
  • Published 14.01.2022 11:15:07
  • Last modified 21.11.2024 06:14:05

A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior...

Exploit
  • EPSS 0.09%
  • Published 06.01.2022 04:15:06
  • Last modified 21.11.2024 06:33:40

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

Exploit
  • EPSS 0.09%
  • Published 06.01.2022 04:15:06
  • Last modified 21.11.2024 06:33:40

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

Exploit
  • EPSS 0.88%
  • Published 01.01.2022 06:15:07
  • Last modified 22.05.2025 15:15:54

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

Exploit
  • EPSS 0.54%
  • Published 01.01.2022 05:15:08
  • Last modified 21.11.2024 06:26:48

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

Exploit
  • EPSS 0.22%
  • Published 25.12.2021 19:15:07
  • Last modified 21.11.2024 06:37:03

vim is vulnerable to Out-of-bounds Read

  • EPSS 0.09%
  • Published 05.05.2021 09:15:07
  • Last modified 21.11.2024 05:54:44

A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions...