Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 1.5% | — | Yast2 Auth ClientAI | 1/9/2026 | 2/9/2026 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads testjoin invocations… | |
| Pendiente de análisis | Alta (8.6) | 1.6% | — | Suse Yast2-usersAI | 1/9/2026 | 2/9/2026 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to… | |
| Pendiente de análisis | Alta (7.5) | 0.48% | — | Yast2-samba-clientAI | 1/9/2026 | 2/9/2026 | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being… | |
| Modificada | Media (5.9) | 0.73% | — | Opensuse Autoyast2 | 3/4/2020 | 17/6/2026 | A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue affects: SUSE Linux Enterprise Server 12… | |
| Modificada | Media (5.5) | 0.43% | — | Yast2-rmt Project Yast2-rmtOpensuse LeapSuse Linux Enterprise Server | 27/1/2020 | 17/6/2026 | A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt… | |
| Modificada | Baja (3.3) | 0.11% | — | Suse Yast2-security | 24/1/2020 | 17/6/2026 | yast2-security didn't use secure defaults to protect passwords. This became a problem on 2019-10-07 when configuration files that set secure settings were moved to a different location. As of the 20191022 snapshot the insecure default settings were used until yast2-security switched to stronger defaults in 4.2.6 and… | |
| Modificada | Alta (8.1) | 1.0% | — | Opensuse Yast2-printer | 15/3/2019 | 17/6/2026 | In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast. | |
| Modificada | Alta (7.8) | 0.34% | — | Opensuse Yast2-samba-provision | 15/3/2019 | 17/6/2026 | In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samba-provision, allowing local attackers to read them in the process list | |
| Modificada | Media (5.5) | 0.31% | — | Opensuse Yast2-multipath | 15/3/2019 | 17/6/2026 | In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection | |
| Modificada | Alta (7.8) | 0.31% | — | Yast2 | 8/9/2017 | 16/6/2026 | The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks. | |
| Modificada | Crítica (9.8) | 2.5% | — | Suse Yast2 | 26/4/2016 | 17/6/2026 | yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.2) | 0.47% | — | Suse Yast2-backup | 27/11/2008 | 16/6/2026 | yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process. |