Skip to main content

Vendor/product archive

opensuse / libzypp CVEs

Beta · best-effort

7 CVEs tagged to opensuse / libzypp0 Critical, 6 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-44941

Published Jul 2, 2026

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or over…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-25707

Published Jun 29, 2026

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-7685

Published Aug 31, 2018

The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RP…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9269

Published Mar 1, 2018

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7436

Published Mar 1, 2018

In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicio…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7435

Published Mar 1, 2018

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicio…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1