CVEs we hold for Opensuse
Records whose assigning authority named Opensuse as the affected vendor. Newest identifiers first, capped at 200.
Announced together
One group of these records was published under a single advisory. Its page names that advisory, counts what the group offers, and says what it does not cover.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
CVE-2026-48863Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceOpenSUSE libsolv; Red Hat Enterprise Linux 10…
CVE-2025-53881SUSE-specific logrotate configuration allows escalation from mail user/group to rootopenSUSE Tumbleweed
CVE-2024-49506Fixed temporary file path in aeon-checks allows fixing of disk encryption keyopenSUSE Tumbleweed
CVE-2022-46163travel-support-program vulnerable to data exfiltration via Ransack query injectionopenSUSE travel-support-program
CVE-2022-31253openldap2: /usr/lib/openldap/start allows ldap user/group to recursively chown arbitrary directory trees to itselfopenSUSE Factory
CVE-2022-31250keylime %post scriplet allows for privilege escalation from keylime user to rootopenSUSE Tumbleweed
CVE-2021-31997python-postorius: postorius-permissions.sh used during %post allows local privilege escalation from postorius user to…openSUSE Factory
CVE-2021-25322python-HyperKitty: hyperkitty-permissions.sh used during %post allows local privilege escalation from hyperkitty user…openSUSE Factory
CVE-2021-25319virtualbox: missing sticky bit for /etc/vbox allows local root exploit for members of vboxusers groupopenSUSE Factory
CVE-2020-8024Problematic permissions in hylafax+ packaging allow escalation from uucp to other usersopenSUSE Factory
CVE-2020-8021unauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build ServiceopenSUSE Open Build Service
CVE-2020-8014kopano-python-services: Local privilege escalation from kopano to root in kopano-spamd subpackageopenSUSE Tumbleweed
CVE-2019-3694Local privilege escalation from munin to root in the packaging of muninopenSUSE Leap 15.1
CVE-2018-12479Request controller allows to create requests with arbitrary request IDsopenSUSE Open Build Service
CVE-2018-12478obs-service-replace_using_package_version allows to specify arbitrary input filesopenSUSE Open Build Service
CVE-2018-12477obs-service-refresh_patches can be tricked into deleting '..' or other unrelated directoriesopenSUSE Open Build Service
CVE-2018-12475obs-service-download_files allows downloading from localhost or intranet hostsopenSUSE Open Build Service
CVE-2018-12474Crafted service parameters allows to induce unexpected behaviour in obs-service-tar_scmopenSUSE Open Build Service
52 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.