Suse / Manager
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-3684 | susemanager installer creates world-readable swap files | MEDIUM | 5.9 | May 13, 2019 |
| CVE-2015-5300 | ntp: MITM attacker can force ntpd to make a step larger than the panic threshold | HIGH | 7.5 | Jul 21, 2017 |
| CVE-2015-5219 | ntp: infinite loop in sntp processing crafted packet | HIGH | 7.5 | Jul 21, 2017 |
| CVE-2015-5194 | ntp: crash with crafted logconfig configuration command | HIGH | 7.5 | Jul 21, 2017 |
| CVE-2017-7995 | xen: Checks access permissions to MMIO ranges only after accessing them | LOW | 3.8 | May 3, 2017 |
| CVE-2015-7976 | ntp: 'ntpq saveconfig' command allows dangerous characters in filenames | MEDIUM | 4.3 | Jan 30, 2017 |
| CVE-2016-4954 | ntp: partial processing of spoofed packets | HIGH | 7.5 | Jul 5, 2016 |
| CVE-2016-4953 | ntp: bad authentication demobilizes ephemeral associations | HIGH | 7.5 | Jul 5, 2016 |
| CVE-2016-0264 | JDK: buffer overflow vulnerability in the IBM JVM | MEDIUM | 5.6 | May 24, 2016 |
| CVE-2016-3718 KEV | ImageMagick: SSRF vulnerability | MEDIUM | 5.5 | May 5, 2016 |
| CVE-2016-3715 KEV | ImageMagick: File deletion | MEDIUM | 5.5 | May 5, 2016 |
| CVE-2016-3427 KEV | OpenJDK: unrestricted deserialization of authentication credentials (JMX, 8144430) | CRITICAL | 9.8 | Apr 21, 2016 |
| CVE-2016-1286 | bind: malformed signature records for DNAME records can trigger assertion failure | HIGH | 8.6 | Mar 9, 2016 |
| CVE-2016-1285 | bind: malformed packet sent to rndc can trigger assertion failure | MEDIUM | 6.8 | Mar 9, 2016 |
| CVE-2014-8162 | Satellite5: RPC API XML External Entities file disclosure | HIGH | 7.5 | May 14, 2015 |
| CVE-2015-2808 | SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher | LOW | 3.7 | Apr 1, 2015 |
| CVE-2014-7812 | Spacewalk: XSS in system-group | LOW | 3.5 | Jan 15, 2015 |
| CVE-2014-7811 | Spacewalk: multiple XSS | LOW | 3.5 | Jan 15, 2015 |
| CVE-2014-3654 | Satellite: Spacewalk contains multiple XSS (stored and reflected) | MEDIUM | 4.3 | Nov 3, 2014 |
| CVE-2014-3595 | Satellite: Spacewalk contains XSS in log file view | MEDIUM | 4.3 | Sep 22, 2014 |
| CVE-2013-4415 | Spacewalk: PAGE_SIZE_LABEL_SELECTED cross-site scripting (XSS) | MEDIUM | 4.3 | Feb 14, 2014 |
| CVE-2013-4480 | Satellite: Interface to create the initial administrator user remains open after installation | HIGH | 7.5 | Nov 15, 2013 |
Showing 1 to 22 of 22 CVEs