<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – openSUSE</title>
  <link>https://cvedaily.com/pages/tags/opensuse.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/opensuse.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – openSUSE</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-25701 – An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25701</guid>
    <pubDate>Wed, 25 Feb 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25701</strong></p>
  <p>An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like:   *  gain access to possible private information found in /var/lib/pcrlock.d   *  manipulate the data backed up in /tmp/pcrlock.d.bak, therefore violating the integrity of the data should it be restored.   *   overwrite protected system files with data from…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62875 – An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62875</guid>
    <pubDate>Thu, 20 Nov 2025 16:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62875</strong></p>
  <p>An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD.     This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46810 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46810</guid>
    <pubDate>Tue, 02 Sep 2025 12:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46810</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53882 – A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53882</guid>
    <pubDate>Wed, 23 Jul 2025 10:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53882</strong></p>
  <p>A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP to arbitrary processes. This issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50177 – In the Linux kernel, the following vulnerability has been resolved:

rcutorture:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50177</guid>
    <pubDate>Wed, 18 Jun 2025 11:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50177</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rcutorture: Fix ksoftirqd boosting timing and iteration  The RCU priority boosting can fail in two situations:  1) If (nr_cpus= > maxcpus=), which means if the total number of CPUs is higher than those brought online at boot, then torture_onoff() may later bring up CPUs that weren't online on boot. Now since rcutorture initializ…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-23394 – A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23394</guid>
    <pubDate>Mon, 26 May 2025 16:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-23394</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed  cyrus-imapd before 3.8.4-2.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53052 – In the Linux kernel, the following vulnerability has been resolved:

cifs: fix u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53052</guid>
    <pubDate>Fri, 02 May 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53052</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cifs: fix use-after-free bug in refresh_cache_worker()  The UAF bug occurred because we were putting DFS root sessions in cifs_umount() while DFS cache refresher was being executed.  Make DFS root sessions have same lifetime as DFS tcons so we can avoid the use-after-free bug is DFS cache refresher and other places that require…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49889 – In the Linux kernel, the following vulnerability has been resolved:

ring-buffer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49889</guid>
    <pubDate>Thu, 01 May 2025 15:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49889</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ring-buffer: Check for NULL cpu_buffer in ring_buffer_wake_waiters()  On some machines the number of listed CPUs may be bigger than the actual CPUs that exist. The tracing subsystem allocates a per_cpu directory with access to the per CPU ring buffer via a cpuX file. But to save space, the ring buffer will only allocate buffers…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23386 – A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23386</guid>
    <pubDate>Thu, 10 Apr 2025 10:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23386</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-21752 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: don'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21752</guid>
    <pubDate>Thu, 27 Feb 2025 03:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-21752</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: don't use btrfs_set_item_key_safe on RAID stripe-extents  Don't use btrfs_set_item_key_safe() to modify the keys in the RAID stripe-tree, as this can lead to corruption of the tree, which is caught by the checks in btrfs_set_item_key_safe():   BTRFS info (device nvme1n1): leaf 49168384 gen 15 total ptrs 194 free space 832…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-58005 – In the Linux kernel, the following vulnerability has been resolved:

tpm: Change...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58005</guid>
    <pubDate>Thu, 27 Feb 2025 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-58005</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  tpm: Change to kvalloc() in eventlog/acpi.c  The following failure was reported on HPE ProLiant D320:  [   10.693310][    T1] tpm_tis STM0925:00: 2.0 TPM (device-id 0x3, rev-id 0) [   10.848132][    T1] ------------[ cut here ]------------ [   10.853559][    T1] WARNING: CPU: 59 PID: 1 at mm/page_alloc.c:4727 __alloc_pages_nopro…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49412 – In the Linux kernel, the following vulnerability has been resolved:

bfq: Avoid ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49412</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49412</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  bfq: Avoid merging queues with different parents  It can happen that the parent of a bfqq changes between the moment we decide two queues are worth to merge (and set bic->stable_merge_bfqq) and the moment bfq_setup_merge() is called. This can happen e.g. because the process submitted IO for a different cgroup and thus bfqq got r…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49271 – In the Linux kernel, the following vulnerability has been resolved:

cifs: preve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49271</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49271</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cifs: prevent bad output lengths in smb2_ioctl_query_info()  When calling smb2_ioctl_query_info() with smb_query_info::flags=PASSTHRU_FSCTL and smb_query_info::output_buffer_length=0, the following would return 0x10  	buffer = memdup_user(arg + sizeof(struct smb_query_info), 			     qi.output_buffer_length); 	if (IS_ERR(buffer))…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-57895 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: set ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57895</guid>
    <pubDate>Wed, 15 Jan 2025 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-57895</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: set ATTR_CTIME flags when setting mtime  David reported that the new warning from setattr_copy_mgtime is coming like the following.  [  113.215316] ------------[ cut here ]------------ [  113.215974] WARNING: CPU: 1 PID: 31 at fs/attr.c:300 setattr_copy+0x1ee/0x200 [  113.219192] CPU: 1 UID: 0 PID: 31 Comm: kworker/1:1 No…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-49505 – A Improper Neutralization of Input During Web Page Generation ('Cross-site Scrip...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49505</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49505</guid>
    <pubDate>Wed, 13 Nov 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-49505</strong></p>
  <p>A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the  REGEX and P parameters. This issue affects MirrorCache before 1.083.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49505">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-48984 – In the Linux kernel, the following vulnerability has been resolved:

can: slcan:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48984</guid>
    <pubDate>Mon, 21 Oct 2024 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-48984</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  can: slcan: fix freed work crash  The LTP test pty03 is causing a crash in slcan:   BUG: kernel NULL pointer dereference, address: 0000000000000008   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not-present page   PGD 0 P4D 0   Oops: 0000 [#1] PREEMPT SMP NOPTI   CPU: 0 PID: 348 Comm: kworker/0:3 Not ta…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-46734 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46734</guid>
    <pubDate>Wed, 18 Sep 2024 08:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-46734</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix race between direct IO write and fsync when using same fd  If we have 2 threads that are using the same file descriptor and one of them is doing direct IO writes while the other is doing fsync, we have a race where we can end up either:  1) Attempt a fsync without holding the inode's lock, triggering an    assertion f…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46687 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46687</guid>
    <pubDate>Fri, 13 Sep 2024 06:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46687</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk()  [BUG] There is an internal report that KASAN is reporting use-after-free, with the following backtrace:    BUG: KASAN: slab-use-after-free in btrfs_check_read_bio+0xa68/0xb70 [btrfs]   Read of size 4 at addr ffff8881117cec28 by task kworker/u16:2/45   C…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52897 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: qgro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52897</guid>
    <pubDate>Wed, 21 Aug 2024 07:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52897</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: qgroup: do not warn on record without old_roots populated  [BUG] There are some reports from the mailing list that since v6.1 kernel, the WARN_ON() inside btrfs_qgroup_account_extent() gets triggered during rescan:    WARNING: CPU: 3 PID: 6424 at fs/btrfs/qgroup.c:2756 btrfs_qgroup_account_extents+0x1ae/0x260 [btrfs]   CP…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38601 – In the Linux kernel, the following vulnerability has been resolved:

ring-buffer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38601</guid>
    <pubDate>Wed, 19 Jun 2024 14:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38601</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ring-buffer: Fix a race between readers and resize checks  The reader code in rb_get_reader_page() swaps a new reader page into the ring buffer by doing cmpxchg on old->list.prev->next to point it to the new page. Following that, if the operation is successful, old->list.next->prev gets updated too. This means the underlying dou…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52751 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52751</guid>
    <pubDate>Tue, 21 May 2024 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52751</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix use-after-free in smb2_query_info_compound()  The following UAF was triggered when running fstests generic/072 with KASAN enabled against Windows Server 2022 and mount options 'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm'    BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423/0x6d0 [ci…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-47228 – In the Linux kernel, the following vulnerability has been resolved:

x86/ioremap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47228</guid>
    <pubDate>Tue, 21 May 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-47228</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  x86/ioremap: Map EFI-reserved memory as encrypted for SEV  Some drivers require memory that is marked as EFI boot services data. In order for this memory to not be re-used by the kernel after ExitBootServices(), efi_mem_reserve() is used to preserve it by inserting a new EFI memory descriptor and marking it with the EFI_MEMORY_R…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35938 – In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35938</guid>
    <pubDate>Sun, 19 May 2024 11:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35938</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: decrease MHI channel buffer length to 8KB  Currently buf_len field of ath11k_mhi_config_qca6390 is assigned with 0, making MHI use a default size, 64KB, to allocate channel buffers. This is likely to fail in some scenarios where system memory is highly fragmented and memory compaction or reclaim is not allowed.  Th…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-48631 – In the Linux kernel, the following vulnerability has been resolved:

ext4: fix b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48631</guid>
    <pubDate>Sun, 28 Apr 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-48631</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ext4: fix bug in extents parsing when eh_entries == 0 and eh_depth > 0  When walking through an inode extents, the ext4_ext_binsearch_idx() function assumes that the extent header has been previously validated.  However, there are no checks that verify that the number of entries (eh->eh_entries) is non-zero when depth is > 0.  A…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52443 – In the Linux kernel, the following vulnerability has been resolved:

apparmor: a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52443</guid>
    <pubDate>Thu, 22 Feb 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52443</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  apparmor: avoid crash when parsed profile name is empty  When processing a packed profile in unpack_profile() described like   "profile :ns::samba-dcerpcd /usr/lib*/samba/{,samba/}samba-dcerpcd {...}"  a string ":samba-dcerpcd" is unpacked as a fully-qualified name and then passed to aa_splitn_fqname().  aa_splitn_fqname() treat…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52434 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52434</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52434</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix potential OOBs in smb2_parse_contexts()  Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts().  This fixes following oops when accessing invalid create contexts from server:    BUG: unable to handle page fault for address: ffff8881178d8cc3   #PF: supervisor read access in ke…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-32182 – A Improper Link Resolution Before File Access ('Link Following') vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32182</guid>
    <pubDate>Tue, 19 Sep 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-32182</strong></p>
  <p>A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1; SUSE Linux Enterprise High Performance Computing 15 SP5: before 3.7.3-150500.3.5…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32184 – A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32184</guid>
    <pubDate>Tue, 19 Sep 2023 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32184</strong></p>
  <p>A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32183 – Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 pac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32183</guid>
    <pubDate>Fri, 07 Jul 2023 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32183</strong></p>
  <p>Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-32181 – A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32181</guid>
    <pubDate>Thu, 01 Jun 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-32181</strong></p>
  <p>A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuration files This issue affects libeconf: before 0.5.2.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-22652 – A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22652</guid>
    <pubDate>Thu, 01 Jun 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-22652</strong></p>
  <p>A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. This issue affects libeconf: before 0.5.2.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-45155 – An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45155</guid>
    <pubDate>Wed, 15 Mar 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45155</strong></p>
  <p>An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the call to the service to delete files and directories on the system of the victim. This issue affects: SUSE openSUSE Factory obs-service-go_modules versions prior to 0.6.1.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45153 – An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45153</guid>
    <pubDate>Wed, 15 Feb 2023 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45153</strong></p>
  <p>An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formul…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21948 – An Improper Neutralization of Input During Web Page Generation ('Cross-site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21948</guid>
    <pubDate>Tue, 07 Feb 2023 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21948</strong></p>
  <p>An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This issue affects: openSUSE paste paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22643 – An Improper Neutralization of Special Elements used in an OS Command ('OS Comman...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22643</guid>
    <pubDate>Tue, 07 Feb 2023 10:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22643</strong></p>
  <p>An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux Enterprise Server for SAP 15-SP3; openSUSE Leap 15.4 allows attackers that can trick users to use specially crafted REPO_ALIAS, REPO_TYPE or REPO_METADATA_PATH settings to execute code as root. This issue affects: SUSE Linux Enterprise Server for SAP…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31254 – A Incorrect Default Permissions vulnerability in rmt-server-regsharing service o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31254</guid>
    <pubDate>Tue, 07 Feb 2023 10:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31254</strong></p>
  <p>A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46163 – Travel support program is a rails app to support the travel support program of o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46163</guid>
    <pubDate>Tue, 10 Jan 2023 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46163</strong></p>
  <p>Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransack query injection. Every deployment of travel-support-program below the patched version is affected. The travel-support-program uses the Ransack library to implement search functionality. In its default configuration, R…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31253 – A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31253</guid>
    <pubDate>Wed, 09 Nov 2022 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31253</strong></p>
  <p>A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31256 – A Improper Link Resolution Before File Access ('Link Following') vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31256</guid>
    <pubDate>Wed, 26 Oct 2022 09:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31256</strong></p>
  <p>A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31252 – A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31252</guid>
    <pubDate>Thu, 06 Oct 2022 18:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31252</strong></p>
  <p>A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged binary to influence path resolution. This issue affects: SUSE Linux Enterprise Se…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28321 – The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28321</guid>
    <pubDate>Mon, 19 Sep 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28321</strong></p>
  <p>The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumblewee…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31251 – A Incorrect Default Permissions vulnerability in the packaging of the slurm test...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31251</guid>
    <pubDate>Wed, 07 Sep 2022 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31251</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21950 – A Improper Access Control vulnerability in the systemd service of cana in openSU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21950</guid>
    <pubDate>Wed, 07 Sep 2022 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21950</strong></p>
  <p>A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Inst…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31250 – A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31250</guid>
    <pubDate>Wed, 20 Jul 2022 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31250</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21946 – A Incorrect Permission Assignment for Critical Resource vulnerability in the sud...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21946</guid>
    <pubDate>Wed, 16 Mar 2022 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21946</strong></p>
  <p>A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21945 – A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21945</guid>
    <pubDate>Wed, 16 Mar 2022 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21945</strong></p>
  <p>A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46705 – A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46705</guid>
    <pubDate>Wed, 16 Mar 2022 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46705</strong></p>
  <p>A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36777 – A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36777</guid>
    <pubDate>Wed, 09 Mar 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36777</strong></p>
  <p>A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-44568 – Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44568</guid>
    <pubDate>Mon, 21 Feb 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-44568</strong></p>
  <p>Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21944 – A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21944</guid>
    <pubDate>Wed, 26 Jan 2022 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21944</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36781 – A Incorrect Default Permissions vulnerability in the parsec package of openSUSE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36781</guid>
    <pubDate>Fri, 14 Jan 2022 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36781</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-32000 – A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32000</guid>
    <pubDate>Wed, 28 Jul 2021 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-32000</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up version 1.6-4.6.1 and prior versions. SUSE Linux Enterpris…</p>
  <p><strong>CVSS:</strong> 3.2 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25321 – A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25321</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25321</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS arpwatch ve…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-31998 – A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31998</guid>
    <pubDate>Thu, 10 Jun 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-31998</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior t…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-31997 – A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31997</guid>
    <pubDate>Thu, 10 Jun 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-31997</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory python-postorius version 1.3.4-2.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25322 – A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25322</guid>
    <pubDate>Thu, 10 Jun 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25322</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions. openSUSE Factory python-HyperKitty versions prior to 1.3.4-5.1.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-25317 – A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25317</guid>
    <pubDate>Wed, 05 May 2021 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-25317</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25319 – A Incorrect Default Permissions vulnerability in the packaging of virtualbox of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25319</guid>
    <pubDate>Wed, 05 May 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25319</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25315 – CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25315</guid>
    <pubDate>Wed, 03 Mar 2021 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25315</strong></p>
  <p>CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE L…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8032 – A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8032</guid>
    <pubDate>Thu, 25 Feb 2021 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8032</strong></p>
  <p>A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8027 – A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8027</guid>
    <pubDate>Thu, 11 Feb 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8027</strong></p>
  <p>A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Serv…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8023 – A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8023</guid>
    <pubDate>Tue, 01 Sep 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8023</strong></p>
  <p>A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-349</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12475 – A Externally Controlled Reference to a Resource in Another Sphere vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12475</guid>
    <pubDate>Tue, 01 Sep 2020 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12475</strong></p>
  <p>A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8026 – A Incorrect Default Permissions vulnerability in the packaging of inn in openSUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8026</guid>
    <pubDate>Fri, 07 Aug 2020 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8026</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 and prior versions. openSUSE Leap 15.1 inn ver…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8025 – A Incorrect Execution-Assigned Permissions vulnerability in the permissions pack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8025</guid>
    <pubDate>Fri, 07 Aug 2020 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8025</strong></p>
  <p>A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissi…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-279</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8019 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8019</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8019</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server for SAP 12-SP1; openSUSE Backports SLE-15-SP1, openSUSE Leap 15…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8014 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8014</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8014</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE Tumbleweed kopano-spamd versions prior to 10.0.5-1.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3681 – A External Control of File Name or Path vulnerability in osc of SUSE Linux Enter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3681</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3681</strong></p>
  <p>A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue affects: SUSE Linux Enterprise…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8024 – A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8024</guid>
    <pubDate>Mon, 29 Jun 2020 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8024</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap 15.1 hylafax+ version 5.6.1-lp151.3.7 and prior versions. openSUSE Factory hylafax…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8020 – A Improper Neutralization of Input During Web Page Generation vulnerability in o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8020</guid>
    <pubDate>Wed, 13 May 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8020</strong></p>
  <p>A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18904 – A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterpris...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18904</guid>
    <pubDate>Fri, 03 Apr 2020 07:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18904</strong></p>
  <p>A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux E…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8017 – A Race Condition Enabling Link Following vulnerability in the cron job shipped w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8017</guid>
    <pubDate>Thu, 02 Apr 2020 14:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8017</strong></p>
  <p>A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Lin…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8016 – A Race Condition Enabling Link Following vulnerability in the packaging of texli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8016</guid>
    <pubDate>Thu, 02 Apr 2020 14:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8016</strong></p>
  <p>A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users to corrupt files or potentially escalate privileges. This issue affects: SUSE Linux Enterpri…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8015 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8015</guid>
    <pubDate>Thu, 02 Apr 2020 08:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8015</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3696 – A Improper Limitation of a Pathname to a Restricted Directory vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3696</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3696</strong></p>
  <p>A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development To…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3695 – A Improper Control of Generation of Code vulnerability in the packaging of pcp o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3695</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3695</strong></p>
  <p>A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18903 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18903</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18903</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18902 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18902</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18902</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked vers…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18897 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18897</guid>
    <pubDate>Mon, 02 Mar 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18897</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 20…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-3698 – UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3698</guid>
    <pubDate>Fri, 28 Feb 2020 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-3698</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7217 – An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7217</guid>
    <pubDate>Tue, 11 Feb 2020 12:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7217</strong></p>
  <p>An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7216 – An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7216</guid>
    <pubDate>Wed, 05 Feb 2020 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7216</strong></p>
  <p>An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-20105 – A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20105</guid>
    <pubDate>Mon, 27 Jan 2020 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-20105</strong></p>
  <p>A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12476 – Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12476</guid>
    <pubDate>Mon, 27 Jan 2020 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12476</strong></p>
  <p>Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUSE Linux Enterprise Server 15 obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74:. openSUSE Factory obs-serv…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3699 – UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3699</guid>
    <pubDate>Fri, 24 Jan 2020 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3699</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3697 – UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3697</guid>
    <pubDate>Fri, 24 Jan 2020 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3697</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3694 – A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3694</guid>
    <pubDate>Fri, 24 Jan 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3694</strong></p>
  <p>A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from user munin to root. This issue affects: openSUSE Factory munin version 2.0.49-4.2 and prior versions. openSUSE Leap 15.1 munin version 2.0.40-lp151.1.1 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3693 – A symlink following vulnerability in the packaging of mailman in SUSE Linux Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3693</guid>
    <pubDate>Fri, 24 Jan 2020 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3693</strong></p>
  <p>A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. This issue affects: SUSE Linux Enterprise Server 11 mailman versions prior to 2.1.15-9.6.15.1. SUSE Linux…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3692 – The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3692</guid>
    <pubDate>Fri, 24 Jan 2020 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3692</strong></p>
  <p>The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.2.47 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3691 – A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3691</guid>
    <pubDate>Thu, 23 Jan 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3691</strong></p>
  <p>A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18899 – The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18899</guid>
    <pubDate>Thu, 23 Jan 2020 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18899</strong></p>
  <p>The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18898 – UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18898</guid>
    <pubDate>Thu, 23 Jan 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18898</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4177 – mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4177</guid>
    <pubDate>Tue, 12 Nov 2019 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4177</strong></p>
  <p>mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-17953 – A incorrect variable in a SUSE specific patch for pam_access rule matching in PA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17953</guid>
    <pubDate>Tue, 27 Nov 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-17953</strong></p>
  <p>A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12479 – A Improper Input Validation vulnerability in Open Build Service allows remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12479</guid>
    <pubDate>Tue, 09 Oct 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12479</strong></p>
  <p>A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12478 – A Improper Input Validation vulnerability in Open Build Service allows remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12478</guid>
    <pubDate>Tue, 09 Oct 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12478</strong></p>
  <p>A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affected releases are openSUSE Open Build Service: status of is unknown.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2018-12477 – A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12477</guid>
    <pubDate>Tue, 09 Oct 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2018-12477</strong></p>
  <p>A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versions prior to d6244245dda5367767efc989446fe4b5e4609cce.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12474 – Improper input validation in obs-service-tar_scm of Open Build Service allows re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12474</guid>
    <pubDate>Tue, 09 Oct 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12474</strong></p>
  <p>Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2018-12473 – A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12473</guid>
    <pubDate>Tue, 02 Oct 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2018-12473</strong></p>
  <p>A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker via KVM. Affected releases are openSUSE Open Build Service: versions prior to 70d1aa4cc4d7b940180553a63805c22fc62e2cf0.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12466 – openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete pac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12466</guid>
    <pubDate>Wed, 01 Aug 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12466</strong></p>
  <p>openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12466">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
