Opensuse
Opensuse Factory: vulnerabilities and CVEs
Opensuse Factory has 10 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31256 | High (7.8) | 0.24% | — | Oct 26, 2022 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue… |
| CVE-2022-31251 | Medium (6.3) | 0.21% | — | Sep 7, 2022 | A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory… |
| CVE-2021-45082 | High (7.8) | 0.50% | — | Feb 19, 2022 | An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines… |
| CVE-2021-36781 | Medium (4.4) | 0.21% | — | Jan 14, 2022 | A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects:… |
| CVE-2021-46142 | Medium (5.5) | 1.1% | — | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. |
| CVE-2021-46141 | Medium (5.5) | 1.1% | — | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. |
| CVE-2021-41819 | High (7.5) | 2.9% | — | Jan 1, 2022 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. |
| CVE-2021-41817 | High (7.5) | 3.2% | — | Jan 1, 2022 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
| CVE-2021-4166 | High (7.1) | 1.6% | — | Dec 25, 2021 | vim is vulnerable to Out-of-bounds Read |
| CVE-2021-25319 | High (7.8) | 0.26% | — | May 5, 2021 | A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox… |