<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – SUSE Linux Enterprise Server (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/sles.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sles-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – SUSE Linux Enterprise Server (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-25702 – A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterpr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25702</guid>
    <pubDate>Thu, 05 Mar 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25702</strong></p>
  <p>A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 before 9c294edb7085fb91650bc12233495a8974c5ff2d.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45153 – An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45153</guid>
    <pubDate>Wed, 15 Feb 2023 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45153</strong></p>
  <p>An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formul…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31254 – A Incorrect Default Permissions vulnerability in rmt-server-regsharing service o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31254</guid>
    <pubDate>Tue, 07 Feb 2023 10:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31254</strong></p>
  <p>A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25321 – A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25321</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25321</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS arpwatch ve…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18906 – A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18906</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18906</strong></p>
  <p>A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25315 – CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25315</guid>
    <pubDate>Wed, 03 Mar 2021 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25315</strong></p>
  <p>CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE L…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8027 – A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8027</guid>
    <pubDate>Thu, 11 Feb 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8027</strong></p>
  <p>A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Serv…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8023 – A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8023</guid>
    <pubDate>Tue, 01 Sep 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8023</strong></p>
  <p>A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-349</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8019 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8019</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8019</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server for SAP 12-SP1; openSUSE Backports SLE-15-SP1, openSUSE Leap 15…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8022 – A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8022</guid>
    <pubDate>Mon, 29 Jun 2020 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8022</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterpr…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8018 – A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8018</guid>
    <pubDate>Mon, 04 May 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8018</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to escalate to root due to a /etc directory owned by the user This issue affects: SUSE Linux Enterprise Server 15 SP1 SLES15-SP1-CAP-Deployment-BYOS version 1.0.1 and prior versions; SLES15-SP1-CHOST-BY…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3696 – A Improper Limitation of a Pathname to a Restricted Directory vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3696</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3696</strong></p>
  <p>A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development To…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3695 – A Improper Control of Generation of Code vulnerability in the packaging of pcp o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3695</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3695</strong></p>
  <p>A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18903 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18903</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18903</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18902 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18902</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18902</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked vers…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18897 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18897</guid>
    <pubDate>Mon, 02 Mar 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18897</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 20…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3693 – A symlink following vulnerability in the packaging of mailman in SUSE Linux Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3693</guid>
    <pubDate>Fri, 24 Jan 2020 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3693</strong></p>
  <p>A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. This issue affects: SUSE Linux Enterprise Server 11 mailman versions prior to 2.1.15-9.6.15.1. SUSE Linux…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3692 – The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3692</guid>
    <pubDate>Fri, 24 Jan 2020 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3692</strong></p>
  <p>The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.2.47 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3691 – A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3691</guid>
    <pubDate>Thu, 23 Jan 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3691</strong></p>
  <p>A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18898 – UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18898</guid>
    <pubDate>Thu, 23 Jan 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18898</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1602 – A code injection in the supportconfig data collection tool in supportutils in SU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1602</guid>
    <pubDate>Thu, 23 Mar 2017 06:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1602</strong></p>
  <p>A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1648 – The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1648</guid>
    <pubDate>Sun, 05 Jul 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1648</strong></p>
  <p>The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0115 – The Device Mapper multipathing driver (aka multipath-tools or device-mapper-mult...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0115</guid>
    <pubDate>Mon, 30 Mar 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0115</strong></p>
  <p>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5471 – libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5471</guid>
    <pubDate>Tue, 16 Oct 2007 00:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5471</strong></p>
  <p>libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request.  NOTE: this issue probably affects other daemons that attempt to initialize this library within a chroot configuration or other invalid configuration.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3655 – Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (nove...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3655</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3655</strong></p>
  <p>Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-2500 – Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2500</guid>
    <pubDate>Mon, 08 Aug 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-2500</strong></p>
  <p>Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-0887 – SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0887</guid>
    <pubDate>Thu, 27 Jan 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-0887</strong></p>
  <p>SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0887">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
