threat
engine
.sh
Back
·
··:··
Home
/
Product
/
opensuse factory
Product
opensuse factory
13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2022-45155
< 0.6.1
An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that c
5.5
MEDIUM
CVE-2022-31256
< 8.17.1-1.1
A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service
7.7
HIGH
CVE-2022-31251
< 22.05.2-3.3
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers w
6.5
MEDIUM
CVE-2021-45082
all versions
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah
7.8
HIGH
CVE-2021-36781
< 0.8.1-1.1
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the serv
5.9
MEDIUM
CVE-2021-46142
all versions
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
5.5
MEDIUM
CVE-2021-46141
all versions
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
5.5
MEDIUM
CVE-2021-41819
all versions
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0
7.5
HIGH
CVE-2021-41817
all versions
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed
7.5
HIGH
CVE-2021-4166
all versions
vim is vulnerable to Out-of-bounds Read
7.1
HIGH
CVE-2021-32000
all versions
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Lin
3.2
LOW
CVE-2021-25319
<= 6.1.20-1.1
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vbo
7.8
HIGH
CVE-2011-1551
all versions
SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin