Home/Product/opensuse factory
Product

opensuse factory

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-45155
< 0.6.1
An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that c
5.5MEDIUM
CVE-2022-31256
< 8.17.1-1.1
A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service
7.7HIGH
CVE-2022-31251
< 22.05.2-3.3
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers w
6.5MEDIUM
CVE-2021-45082
all versions
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah
7.8HIGH
CVE-2021-36781
< 0.8.1-1.1
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the serv
5.9MEDIUM
CVE-2021-46142
all versions
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
5.5MEDIUM
CVE-2021-46141
all versions
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
5.5MEDIUM
CVE-2021-41819
all versions
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0
7.5HIGH
CVE-2021-41817
all versions
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed
7.5HIGH
CVE-2021-4166
all versions
vim is vulnerable to Out-of-bounds Read
7.1HIGH
CVE-2021-32000
all versions
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Lin
3.2LOW
CVE-2021-25319
<= 6.1.20-1.1
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vbo
7.8HIGH
CVE-2011-1551
all versions
SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin