<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – openSUSE (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/opensuse.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/opensuse-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – openSUSE (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-25701 – An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25701</guid>
    <pubDate>Wed, 25 Feb 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25701</strong></p>
  <p>An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like:   *  gain access to possible private information found in /var/lib/pcrlock.d   *  manipulate the data backed up in /tmp/pcrlock.d.bak, therefore violating the integrity of the data should it be restored.   *   overwrite protected system files with data from…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46810 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46810</guid>
    <pubDate>Tue, 02 Sep 2025 12:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46810</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-23394 – A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23394</guid>
    <pubDate>Mon, 26 May 2025 16:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-23394</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed  cyrus-imapd before 3.8.4-2.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53052 – In the Linux kernel, the following vulnerability has been resolved:

cifs: fix u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53052</guid>
    <pubDate>Fri, 02 May 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53052</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cifs: fix use-after-free bug in refresh_cache_worker()  The UAF bug occurred because we were putting DFS root sessions in cifs_umount() while DFS cache refresher was being executed.  Make DFS root sessions have same lifetime as DFS tcons so we can avoid the use-after-free bug is DFS cache refresher and other places that require…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23386 – A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23386</guid>
    <pubDate>Thu, 10 Apr 2025 10:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23386</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49412 – In the Linux kernel, the following vulnerability has been resolved:

bfq: Avoid ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49412</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49412</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  bfq: Avoid merging queues with different parents  It can happen that the parent of a bfqq changes between the moment we decide two queues are worth to merge (and set bic->stable_merge_bfqq) and the moment bfq_setup_merge() is called. This can happen e.g. because the process submitted IO for a different cgroup and thus bfqq got r…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46687 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46687</guid>
    <pubDate>Fri, 13 Sep 2024 06:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46687</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk()  [BUG] There is an internal report that KASAN is reporting use-after-free, with the following backtrace:    BUG: KASAN: slab-use-after-free in btrfs_check_read_bio+0xa68/0xb70 [btrfs]   Read of size 4 at addr ffff8881117cec28 by task kworker/u16:2/45   C…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52751 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52751</guid>
    <pubDate>Tue, 21 May 2024 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52751</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix use-after-free in smb2_query_info_compound()  The following UAF was triggered when running fstests generic/072 with KASAN enabled against Windows Server 2022 and mount options 'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm'    BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423/0x6d0 [ci…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52434 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52434</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52434</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix potential OOBs in smb2_parse_contexts()  Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts().  This fixes following oops when accessing invalid create contexts from server:    BUG: unable to handle page fault for address: ffff8881178d8cc3   #PF: supervisor read access in ke…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32184 – A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32184</guid>
    <pubDate>Tue, 19 Sep 2023 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32184</strong></p>
  <p>A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32183 – Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 pac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32183</guid>
    <pubDate>Fri, 07 Jul 2023 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32183</strong></p>
  <p>Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45153 – An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45153</guid>
    <pubDate>Wed, 15 Feb 2023 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45153</strong></p>
  <p>An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formul…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31254 – A Incorrect Default Permissions vulnerability in rmt-server-regsharing service o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31254</guid>
    <pubDate>Tue, 07 Feb 2023 10:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31254</strong></p>
  <p>A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46163 – Travel support program is a rails app to support the travel support program of o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46163</guid>
    <pubDate>Tue, 10 Jan 2023 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46163</strong></p>
  <p>Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransack query injection. Every deployment of travel-support-program below the patched version is affected. The travel-support-program uses the Ransack library to implement search functionality. In its default configuration, R…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31253 – A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31253</guid>
    <pubDate>Wed, 09 Nov 2022 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31253</strong></p>
  <p>A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31256 – A Improper Link Resolution Before File Access ('Link Following') vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31256</guid>
    <pubDate>Wed, 26 Oct 2022 09:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31256</strong></p>
  <p>A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28321 – The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28321</guid>
    <pubDate>Mon, 19 Sep 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28321</strong></p>
  <p>The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumblewee…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31250 – A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31250</guid>
    <pubDate>Wed, 20 Jul 2022 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31250</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36777 – A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36777</guid>
    <pubDate>Wed, 09 Mar 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36777</strong></p>
  <p>A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21944 – A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21944</guid>
    <pubDate>Wed, 26 Jan 2022 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21944</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25321 – A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25321</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25321</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS arpwatch ve…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25319 – A Incorrect Default Permissions vulnerability in the packaging of virtualbox of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25319</guid>
    <pubDate>Wed, 05 May 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25319</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25315 – CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25315</guid>
    <pubDate>Wed, 03 Mar 2021 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25315</strong></p>
  <p>CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE L…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8027 – A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8027</guid>
    <pubDate>Thu, 11 Feb 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8027</strong></p>
  <p>A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Serv…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8023 – A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8023</guid>
    <pubDate>Tue, 01 Sep 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8023</strong></p>
  <p>A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-349</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8026 – A Incorrect Default Permissions vulnerability in the packaging of inn in openSUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8026</guid>
    <pubDate>Fri, 07 Aug 2020 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8026</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 and prior versions. openSUSE Leap 15.1 inn ver…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8019 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8019</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8019</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server for SAP 12-SP1; openSUSE Backports SLE-15-SP1, openSUSE Leap 15…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8014 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8014</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8014</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE Tumbleweed kopano-spamd versions prior to 10.0.5-1.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3681 – A External Control of File Name or Path vulnerability in osc of SUSE Linux Enter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3681</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3681</strong></p>
  <p>A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue affects: SUSE Linux Enterprise…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8015 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8015</guid>
    <pubDate>Thu, 02 Apr 2020 08:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8015</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3696 – A Improper Limitation of a Pathname to a Restricted Directory vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3696</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3696</strong></p>
  <p>A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development To…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3695 – A Improper Control of Generation of Code vulnerability in the packaging of pcp o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3695</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3695</strong></p>
  <p>A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18903 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18903</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18903</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18902 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18902</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18902</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked vers…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18897 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18897</guid>
    <pubDate>Mon, 02 Mar 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18897</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 20…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7217 – An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7217</guid>
    <pubDate>Tue, 11 Feb 2020 12:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7217</strong></p>
  <p>An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7216 – An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7216</guid>
    <pubDate>Wed, 05 Feb 2020 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7216</strong></p>
  <p>An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3699 – UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3699</guid>
    <pubDate>Fri, 24 Jan 2020 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3699</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3697 – UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3697</guid>
    <pubDate>Fri, 24 Jan 2020 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3697</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3694 – A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3694</guid>
    <pubDate>Fri, 24 Jan 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3694</strong></p>
  <p>A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from user munin to root. This issue affects: openSUSE Factory munin version 2.0.49-4.2 and prior versions. openSUSE Leap 15.1 munin version 2.0.40-lp151.1.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3693 – A symlink following vulnerability in the packaging of mailman in SUSE Linux Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3693</guid>
    <pubDate>Fri, 24 Jan 2020 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3693</strong></p>
  <p>A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. This issue affects: SUSE Linux Enterprise Server 11 mailman versions prior to 2.1.15-9.6.15.1. SUSE Linux…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3692 – The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3692</guid>
    <pubDate>Fri, 24 Jan 2020 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3692</strong></p>
  <p>The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.2.47 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3691 – A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3691</guid>
    <pubDate>Thu, 23 Jan 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3691</strong></p>
  <p>A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18898 – UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18898</guid>
    <pubDate>Thu, 23 Jan 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18898</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-17953 – A incorrect variable in a SUSE specific patch for pam_access rule matching in PA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17953</guid>
    <pubDate>Tue, 27 Nov 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-17953</strong></p>
  <p>A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-3224 – Open Shortest Path First (OSPF) protocol implementations may improperly determin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3224</guid>
    <pubDate>Tue, 24 Jul 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-3224</strong></p>
  <p>Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge. In a case where the sequence numbers are the same, the LSA with the larger chec…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-5220 – The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5220</guid>
    <pubDate>Fri, 08 Jun 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-5220</strong></p>
  <p>The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-7689 – Lack of permission checks in the InitializeDevelPackage function in openSUSE Ope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7689</guid>
    <pubDate>Thu, 07 Jun 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-7689</strong></p>
  <p>Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-7688 – A missing permission check in the review handling of openSUSE Open Build Service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7688</guid>
    <pubDate>Thu, 07 Jun 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-7688</strong></p>
  <p>A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9286 – The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9286</guid>
    <pubDate>Thu, 01 Mar 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9286</strong></p>
  <p>The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-0469 – Code injection in openSUSE when running some source services used in the open bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0469</guid>
    <pubDate>Thu, 17 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-0469</strong></p>
  <p>Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-4007 – Multiple unspecified vulnerabilities in the obs-service-extract_file package bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4007</guid>
    <pubDate>Wed, 13 Apr 2016 14:59:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-4007</strong></p>
  <p>Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to execute arbitrary commands via a service definition, related to executing unzip with "illegal options."</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4159 – ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files secure...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4159</guid>
    <pubDate>Wed, 06 Aug 2014 18:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4159</strong></p>
  <p>ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config/gdb_backtrace, and (5) include/ctdb_private.h.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3110 – Multiple buffer overflows in the Novell Client novfs module for the Linux kernel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3110</guid>
    <pubDate>Tue, 12 Oct 2010 20:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3110</strong></p>
  <p>Multiple buffer overflows in the Novell Client novfs module for the Linux kernel in SUSE Linux Enterprise 11 SP1 and openSUSE 11.3 allow local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-2532 – lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2532</guid>
    <pubDate>Fri, 03 Sep 2010 20:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-2532</strong></p>
  <p>lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0230 – SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0230</guid>
    <pubDate>Fri, 22 Jan 2010 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0230</strong></p>
  <p>SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0115 – The Device Mapper multipathing driver (aka multipath-tools or device-mapper-mult...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0115</guid>
    <pubDate>Mon, 30 Mar 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0115</strong></p>
  <p>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0310 – Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0310</guid>
    <pubDate>Wed, 18 Feb 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0310</strong></p>
  <p>Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors related to "incoming data and authentication-strings."</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3188 – libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration sp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3188</guid>
    <pubDate>Tue, 22 Jul 2008 16:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3188</strong></p>
  <p>libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2388 – Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2388</guid>
    <pubDate>Fri, 06 Jun 2008 22:32:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2388</strong></p>
  <p>Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified impact and attack vectors.  NOTE: the vendor states that these "can be considered no security problem."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-0731 – The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly han...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0731</guid>
    <pubDate>Tue, 12 Feb 2008 21:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-0731</strong></p>
  <p>The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor change_hat system call, which might allow attackers to trigger the unconfining of an apparmored task.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0731">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
