Skip to main content

Vendor archive

opensuse CVEs

Beta · best-effort

3,282 CVEs tagged to vendor opensuse427 Critical, 1,220 High, 1,398 Medium, 237 Low, 0 Unrated.

CVE-2026-44941

Published Jul 2, 2026

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or over…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-25707

Published Jun 29, 2026

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-25506

Published Feb 10, 2026

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNG…

CVSS 7.7 · High
evidence mentions
22
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2025-62875

Published Nov 20, 2025

An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32463

Published Jun 30, 2025

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVSS 9.3 · Critical
evidence mentions
8
Buzz score
78.5
KEV listedPublic PoC observed

CVE-2024-49505

Published Nov 13, 2024

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via re…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32184

Published Sep 19, 2023

A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom la…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32183

Published Jul 7, 2023

Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumb…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32181

Published Jun 1, 2023

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuration files This issue affects lib…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22652

Published Jun 1, 2023

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. This issue affects libeconf: b…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-21948

Published Feb 7, 2023

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This iss…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46163

Published Jan 10, 2023

Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31253

Published Nov 9, 2022

A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory ent…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31256

Published Oct 26, 2022

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to esc…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28321

Published Sep 19, 2022

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tri…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 3,282 CVEsPage 1 of 132