VYPR

Tumbleweed

by OpenSUSE

CVEs (5)

  • CVE-2020-8026HigAug 7, 2020
    risk 0.55cvss 8.4epss 0.00

    A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version…

  • CVE-2023-32183HigJul 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed.

  • CVE-2022-31250HigJul 20, 2022
    risk 0.46cvss 7.1epss 0.00

    A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.

  • CVE-2024-49505MedNov 13, 2024
    risk 0.40cvss 6.1epss 0.00

    A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the  REGEX and P parameters. This issue affects MirrorCache before 1.083.

  • CVE-2025-62875MedNov 20, 2025
    risk 0.29cvss 5.5epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.