VYPR

Factory

by OpenSUSE

CVEs (33)

  • CVE-2021-36781MedJan 14, 2022
    risk 0.38cvss 5.9epss 0.00

    A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.

  • CVE-2019-3698MedFeb 28, 2020
    risk 0.37cvss 5.7epss 0.01

    UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This…

  • CVE-2022-21946MedMar 16, 2022
    risk 0.34cvss 5.3epss 0.00

    A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue…

  • CVE-2022-21945MedMar 16, 2022
    risk 0.33cvss 5.1epss 0.00

    A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

  • CVE-2018-12476MedJan 27, 2020
    risk 0.28cvss 4.3epss 0.01

    Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects:…

  • CVE-2021-32000LowJul 28, 2021
    risk 0.21cvss 3.2epss 0.00

    A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue…

  • CVE-2021-25317LowMay 5, 2021
    risk 0.21cvss 3.3epss 0.00

    A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root…

  • CVE-2019-3700LowJan 24, 2020
    risk 0.19cvss 2.9epss 0.00

    yast2-security didn't use secure defaults to protect passwords. This became a problem on 2019-10-07 when configuration files that set secure settings were moved to a different location. As of the 20191022 snapshot the insecure default settings were used until yast2-security…

  • CVE-2021-45082HigFeb 19, 2022
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

  • CVE-2021-46142MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

  • CVE-2021-46141MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

  • CVE-2021-4166HigDec 25, 2021
    risk 0.00cvss 7.1epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2011-1551Mar 30, 2011
    risk 0.00cvss epss 0.00

    SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.

Page 2 of 2