openSUSE / Factory
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-31253 | openldap2: /usr/lib/openldap/start allows ldap user/group to recursively chown arbitrary directory trees to itself | HIGH | 7.8 | Nov 9, 2022 |
| CVE-2022-31256 | sendmail: mail to root privilege escalation via sm-client.pre script | HIGH | 7.8 | Oct 26, 2022 |
| CVE-2022-31251 | slurm: %post for slurm-testsuite operates as root in user owned directory | MEDIUM | 6.5 | Sep 7, 2022 |
| CVE-2022-21946 | suddoers configuration for cscreen not restrictive enough | MEDIUM | 5.3 | Mar 16, 2022 |
| CVE-2022-21945 | cscreen: usage of fixed path /tmp/cscreen.debug | MEDIUM | 6.1 | Mar 16, 2022 |
| CVE-2021-45082 | cobbler: incomplete template sanitization | HIGH | 8.5 | Feb 18, 2022 |
| CVE-2022-21944 | watchman: chown in watchman@.socket unit allows symlink attack | HIGH | 7.8 | Jan 26, 2022 |
| CVE-2021-36781 | parsec: dangerous 777 permissions for /run/parsec | MEDIUM | 5.9 | Jan 14, 2022 |
| CVE-2021-46141 | uriparser: Invalid free operations in uriFreeUriMembers and uriMakeOwner | MEDIUM | 5.5 | Jan 6, 2022 |
| CVE-2021-46142 | uriparser: Invalid free operations in uriNormalizeSyntax. | MEDIUM | 5.5 | Jan 6, 2022 |
| CVE-2021-41819 | ruby: Cookie prefix spoofing in CGI::Cookie.parse | HIGH | 7.5 | Jan 1, 2022 |
| CVE-2021-41817 | ruby: Regular expression denial of service vulnerability of Date parsing methods | HIGH | 7.5 | Jan 1, 2022 |
| CVE-2021-4166 | Out-of-bounds Read in vim/vim | HIGH | 7.1 | Dec 25, 2021 |
| CVE-2021-32000 | clone-master-clean-up: dangerous file system operations | HIGH | 7.1 | Jul 28, 2021 |
| CVE-2021-25321 | arpwatch: Local privilege escalation from runtime user to root | HIGH | 7.8 | Jun 30, 2021 |
| CVE-2021-25322 | python-HyperKitty: hyperkitty-permissions.sh used during %post allows local privilege escalation from hyperkitty user to root | HIGH | 7.8 | Jun 10, 2021 |
| CVE-2021-31997 | python-postorius: postorius-permissions.sh used during %post allows local privilege escalation from postorius user to root | HIGH | 7.8 | Jun 10, 2021 |
| CVE-2021-25317 | cups: ownership of /var/log/cups allows the lp user to create files as root | LOW | 3.3 | May 5, 2021 |
| CVE-2021-25319 | virtualbox: missing sticky bit for /etc/vbox allows local root exploit for members of vboxusers group | HIGH | 7.8 | May 5, 2021 |
| CVE-2020-8032 | Local privilege escalation to root due to insecure tmp file usage | HIGH | 7.0 | Feb 25, 2021 |
| CVE-2020-8015 | Local privilege escalation in exim package from user mail to root | HIGH | 8.4 | Apr 2, 2020 |
| CVE-2019-18903 | wicked: Use-after-free when receiving invalid DHCP6 IA_PD option | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2019-18902 | wicked: Use-after-free when receiving invalid DHCP6 client options | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2019-18897 | Local privilege escalation from user salt to root | HIGH | 8.4 | Mar 2, 2020 |
| CVE-2019-3698 | nagios cron job allows privilege escalation from user nagios to root | HIGH | 7.0 | Feb 28, 2020 |
Showing 1 to 24 of 24 CVEs