Vulnerabilidades en OpenSUSE

81 resultados
Análisis Vexday

O OpenSUSE apresenta uma vulnerabilidade catalogada na base Vexday, publicada recentemente (últimos 90 dias), classificada como estouro de buffer (CWE-121), mas sem exploração ativa conhecida nem severidade crítica. O risco atual é contido e não figura nas prioridades de resposta imediata, embora justifique monitoramento contínuo.

CVE-2019-3695HIGHpcp: Local privilege escalation from user pcp to rootEPSS 0.5%CVE-2026-48863HIGHLibsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceEPSS 0.5%CVE-2019-3696HIGHpcp: Local privilege escalation from user pcp to root through migrate_tempdirsEPSS 0.5%CVE-2021-25321HIGHarpwatch: Local privilege escalation from runtime user to rootEPSS 0.4%CVE-2021-25322MEDIUMpython-HyperKitty: hyperkitty-permissions.sh used during %post allows local privilege escalation from hyperkitty user to rootEPSS 0.4%CVE-2018-20105MEDIUMyast2-rmt exposes CA private key passhrase in log-fileEPSS 0.4%CVE-2019-3694HIGHLocal privilege escalation from munin to root in the packaging of muninEPSS 0.4%CVE-2019-3699HIGHLocal privilege escalation from user privoxy to rootEPSS 0.4%CVE-2020-8023HIGHLocal privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2EPSS 0.4%CVE-2019-18897HIGHLocal privilege escalation from user salt to rootEPSS 0.4%CVE-2020-8032MEDIUMLocal privilege escalation to root due to insecure tmp file usageEPSS 0.4%CVE-2026-56004CRITICALobs-service-tar_scm: command injection via mercurial handlerEPSS 0.4%CVE-2019-3693HIGHLocal privilege escalation from user wwwrun to root in the packaging of mailmanEPSS 0.4%CVE-2020-8026HIGHinn: non-root owned filesEPSS 0.4%CVE-2021-31997MEDIUMpython-postorius: postorius-permissions.sh used during %post allows local privilege escalation from postorius user to rootEPSS 0.3%CVE-2022-31253HIGHopenldap2: /usr/lib/openldap/start allows ldap user/group to recursively chown arbitrary directory trees to itselfEPSS 0.3%CVE-2022-31250HIGHkeylime %post scriplet allows for privilege escalation from keylime user to rootEPSS 0.3%CVE-2024-49505MEDIUMXSS vulnerability found in OpenSuse MirrorCacheEPSS 0.3%CVE-2021-31998MEDIUMinn: %post calls user owned file allowing local privilege escalation to rootEPSS 0.3%CVE-2020-8027HIGHopenldap uses fixed paths in /tmpEPSS 0.3%