CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

opensuse

factory

10 known vulnerabilities · sorted by CVSS score

CVE-2021-45082
HIGH7.8

An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

cobbler_project / cobbler+10
Local
Published Feb 19, 2022
CVE-2021-25319
HIGH7.8

A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.

opensuse / factory
Local
Published May 5, 2021
CVE-2022-31256
HIGH7.7

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

opensuse / factory
Local
Published Oct 26, 2022
CVE-2021-41817
HIGH7.5

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

ruby-lang / date+18
Network
Published Jan 1, 2022
CVE-2021-41819
HIGH7.5

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

ruby-lang / cgi+17
Network
Published Jan 1, 2022
CVE-2021-4166
HIGH7.1

vim is vulnerable to Out-of-bounds Read

vim / vim+25
Local
Published Dec 25, 2021
CVE-2022-31251
MEDIUM6.5

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.

opensuse / factory
Local
Published Sep 7, 2022
CVE-2021-36781
MEDIUM5.9

A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.

opensuse / factory
Local
Published Jan 14, 2022
CVE-2021-46142
MEDIUM5.5

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

uriparser_project / uriparser+9
Local
Published Jan 6, 2022
CVE-2021-46141
MEDIUM5.5

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

uriparser_project / uriparser+9
Local
Published Jan 6, 2022