openSUSE Vulnerabilities and Affected Products
Vulnerabilities associated with leap.
Products
Clear product- Factory24 vulnerabilities
- Open Build Service13 vulnerabilities
- openSUSE Leap 15.113 vulnerabilities
- Leap 15.18 vulnerabilities
- Tumbleweed7 vulnerabilities
- openSUSE Leap 15.26 vulnerabilities
- openSUSE Leap 15.44 vulnerabilities
- leap3 vulnerabilities
- Leap 15.23 vulnerabilities
- openbuildservice3 vulnerabilities
- openSUSE Tumbleweed3 vulnerabilities
- libeconf2 vulnerabilities
- opensuse2 vulnerabilities
- openSUSE Backports SLE-15-SP32 vulnerabilities
- openSUSE Factory2 vulnerabilities
- openSUSE Leap 15.32 vulnerabilities
- Build service1 vulnerability
- buildservice1 vulnerability
- libsolv1 vulnerability
- obs-service-set_version1 vulnerability
- open-build-service1 vulnerability
- openSUSE Backports SLE-15-SP11 vulnerability
- openSUSE Backports SLE-15-SP21 vulnerability
- openSUSE Backports SLE-15-SP41 vulnerability
- openSUSE Leap Micro 5.21 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-20105MEDIUM | yast2-rmt exposes CA private key passhrase in log-fileA Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2. CWE-532Jan 27, 2020 | CVSS4.0v3.1 | EPSS0.425% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
opensuse leap Missing AuthorizationThe AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check. CWE-862Mar 20, 2017 | CVSS2.7v3.1 | EPSS15% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2016-3714HIGH | ImageMagick Improper Input Validation VulnerabilityThe (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick." CWE-20May 5, 2016 | CVSS8.4v3.1 | EPSS97.5% | PoCs13 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |