Showing 3 vulnerabilities on this page for leap

Signals CISA KEV Ransomware Nuclei
openSUSE vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

yast2-rmt exposes CA private key passhrase in log-file

A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.

CWE-532Jan 27, 2020
CVSS4.0v3.1EPSS0.425%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

opensuse leap Missing Authorization

The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.

CWE-862Mar 20, 2017
CVSS2.7v3.1EPSS15%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick Improper Input Validation Vulnerability

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

CWE-20May 5, 2016
CVSS8.4v3.1EPSS97.5%PoCs13SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX