Opensuse
Vendor:
First CVE: May 14, 2007 · Active for 19 years
9
Total CVEs
More Total CVEs than 77% of tracked products
1.8
Avg CVEs / Year
Bottom 1%
6.1
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Opensuse over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2007
19 years ago
Most Recent CVE
Jul 24, 2018
2,922 days ago
CVE Severity & Scoring
Opensuse9 CVEs
22%
33%
33%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (11.1%)
Unknown7 (77.8%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low1 (11.1%)
High1 (11.1%)
Unknown7 (77.8%)
User Interaction
None2 (22.2%)
Unknown7 (77.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (22.2%)
Unknown7 (77.8%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0411MEDIUM Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file con | Feb 28, 2008 | 6.8 | 33 | NO | YES |
CVE-2011-0469CRITICAL Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011. | Aug 17, 2017 | 9.8 | 29 | NO | NO |
CVE-2010-0230HIGH SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access rest | Jan 22, 2010 | 7.5 | 22 | NO | NO |
CVE-2017-3224HIGH Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 sect | Jul 24, 2018 | 8.2 | 21 | NO | NO |
CVE-2008-0731HIGH The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor change_hat system call, which might allow attackers to trigger the unconf | Feb 12, 2008 | 7.5 | 21 | NO | NO |
acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling. | Mar 6, 2008 | 3.7 | 16 | NO | NO |
CVE-2008-2667MEDIUM SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Lati | Jul 7, 2008 | 5.1 | 15 | NO | NO |
CVE-2007-2654MEDIUM xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems. | May 14, 2007 | 4.4 | 14 | NO | NO |
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent proces | Jul 7, 2008 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Opensuse
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.2 | 1 | 7.5 | 1.8% | 0 | 0 |
| 10.3 | 1 | 2.1 | 0.3% | 0 | 0 |
| 10.2 | 1 | 4.4 | 0.3% | 0 | 0 |