opensuse_project CVE Vulnerabilities & Metrics

Focus on opensuse_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About opensuse_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with opensuse_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total opensuse_project CVEs: 38
Earliest CVE date: 18 Jul 2012, 23:55 UTC
Latest CVE date: 20 Dec 2017, 23:29 UTC

Latest CVE reference: CVE-2017-17806

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical opensuse_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.42

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 42
7.0-8.9 7
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS opensuse_project CVEs

These are the five CVEs with the highest CVSS scores for opensuse_project, sorted by severity first and recency.

All CVEs for opensuse_project

CVE-2017-17806 opensuse_project vulnerability CVSS: 7.2 20 Dec 2017, 23:29 UTC

The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.

CVE-2017-17805 opensuse_project vulnerability CVSS: 7.2 20 Dec 2017, 23:29 UTC

The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified other impact by executing a crafted sequence of system calls that use the blkcipher_walk API. Both the generic implementation (crypto/salsa20_generic.c) and x86 implementation (arch/x86/crypto/salsa20_glue.c) of Salsa20 were vulnerable.

CVE-2016-1254 opensuse_project vulnerability CVSS: 5.0 05 Dec 2017, 16:29 UTC

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

CVE-2015-3138 opensuse_project vulnerability CVSS: 5.0 28 Sep 2017, 01:29 UTC

print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).

CVE-2014-4616 opensuse_project vulnerability CVSS: 4.3 24 Aug 2017, 20:29 UTC

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVE-2015-3405 opensuse_project vulnerability CVSS: 5.0 09 Aug 2017, 16:29 UTC

ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.

CVE-2015-5203 opensuse_project vulnerability CVSS: 4.3 02 Aug 2017, 19:29 UTC

Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

CVE-2015-5221 opensuse_project vulnerability CVSS: 4.3 25 Jul 2017, 18:29 UTC

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

CVE-2016-9961 opensuse_project vulnerability CVSS: 10.0 06 Jun 2017, 18:29 UTC

game-music-emu before 0.6.1 mishandles unspecified integer values.

CVE-2016-9960 opensuse_project vulnerability CVSS: 2.1 06 Jun 2017, 18:29 UTC

game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).

CVE-2016-9959 opensuse_project vulnerability CVSS: 6.8 12 Apr 2017, 20:59 UTC

game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.

CVE-2016-9958 opensuse_project vulnerability CVSS: 6.8 12 Apr 2017, 20:59 UTC

game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.

CVE-2016-9957 opensuse_project vulnerability CVSS: 6.8 12 Apr 2017, 20:59 UTC

Stack-based buffer overflow in game-music-emu before 0.6.1.

CVE-2017-6542 opensuse_project vulnerability CVSS: 7.5 27 Mar 2017, 17:59 UTC

The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.

CVE-2015-8010 opensuse_project vulnerability CVSS: 4.3 27 Mar 2017, 17:59 UTC

Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.

CVE-2016-7797 opensuse_project vulnerability CVSS: 5.0 24 Mar 2017, 15:59 UTC

Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.

CVE-2016-9556 opensuse_project vulnerability CVSS: 4.3 23 Mar 2017, 18:59 UTC

The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.

CVE-2016-10048 opensuse_project vulnerability CVSS: 5.0 23 Mar 2017, 17:59 UTC

Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.

CVE-2014-9851 opensuse_project vulnerability CVSS: 5.0 20 Mar 2017, 16:59 UTC

ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).

CVE-2014-9850 opensuse_project vulnerability CVSS: 5.0 20 Mar 2017, 16:59 UTC

Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).

CVE-2014-9849 opensuse_project vulnerability CVSS: 5.0 20 Mar 2017, 16:59 UTC

The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).

CVE-2014-9848 opensuse_project vulnerability CVSS: 5.0 20 Mar 2017, 16:59 UTC

Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).

CVE-2014-9847 opensuse_project vulnerability CVSS: 7.5 20 Mar 2017, 16:59 UTC

The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.

CVE-2014-9846 opensuse_project vulnerability CVSS: 7.5 20 Mar 2017, 16:59 UTC

Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.

CVE-2014-9845 opensuse_project vulnerability CVSS: 4.3 20 Mar 2017, 16:59 UTC

The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.

CVE-2014-9844 opensuse_project vulnerability CVSS: 4.3 20 Mar 2017, 16:59 UTC

The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.

CVE-2014-9843 opensuse_project vulnerability CVSS: 7.5 20 Mar 2017, 16:59 UTC

The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.

CVE-2014-9842 opensuse_project vulnerability CVSS: 5.0 20 Mar 2017, 16:59 UTC

Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

CVE-2014-9841 opensuse_project vulnerability CVSS: 7.5 20 Mar 2017, 16:59 UTC

The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."

CVE-2014-9853 opensuse_project vulnerability CVSS: 4.3 17 Mar 2017, 14:59 UTC

Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.

CVE-2017-5938 opensuse_project vulnerability CVSS: 4.3 15 Mar 2017, 14:59 UTC

Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

CVE-2016-10069 opensuse_project vulnerability CVSS: 4.3 02 Mar 2017, 21:59 UTC

coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.

CVE-2016-10068 opensuse_project vulnerability CVSS: 4.3 02 Mar 2017, 21:59 UTC

The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.

CVE-2016-9436 opensuse_project vulnerability CVSS: 4.3 20 Jan 2017, 15:59 UTC

parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.

CVE-2016-9435 opensuse_project vulnerability CVSS: 4.3 20 Jan 2017, 15:59 UTC

The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.

CVE-2016-5317 opensuse_project vulnerability CVSS: 4.3 20 Jan 2017, 15:59 UTC

Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.

CVE-2016-5316 opensuse_project vulnerability CVSS: 4.3 20 Jan 2017, 15:59 UTC

Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.

CVE-2015-5218 opensuse_project vulnerability CVSS: 2.1 09 Nov 2015, 16:59 UTC

Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable.

CVE-2014-0481 opensuse_project vulnerability CVSS: 4.3 26 Aug 2014, 14:55 UTC

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

CVE-2014-4258 opensuse_project vulnerability CVSS: 6.5 17 Jul 2014, 11:17 UTC

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.

CVE-2014-3004 opensuse_project vulnerability CVSS: 4.3 11 Jun 2014, 14:55 UTC

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

CVE-2014-1542 opensuse_project vulnerability CVSS: 6.8 11 Jun 2014, 10:57 UTC

Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.

CVE-2014-1528 opensuse_project vulnerability CVSS: 10.0 30 Apr 2014, 10:49 UTC

The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.

CVE-2014-1502 opensuse_project vulnerability CVSS: 6.8 19 Mar 2014, 10:55 UTC

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

CVE-2014-1500 opensuse_project vulnerability CVSS: 5.0 19 Mar 2014, 10:55 UTC

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.

CVE-2014-1499 opensuse_project vulnerability CVSS: 4.3 19 Mar 2014, 10:55 UTC

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

CVE-2014-1498 opensuse_project vulnerability CVSS: 5.0 19 Mar 2014, 10:55 UTC

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.

CVE-2014-1494 opensuse_project vulnerability CVSS: 9.3 19 Mar 2014, 10:55 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2014-0081 opensuse_project vulnerability CVSS: 4.3 20 Feb 2014, 15:27 UTC

Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.

CVE-2011-4093 opensuse_project vulnerability CVSS: 5.8 10 Feb 2014, 18:15 UTC

Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.

CVE-2014-1489 opensuse_project vulnerability CVSS: 4.3 06 Feb 2014, 05:44 UTC

Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.

CVE-2014-1484 opensuse_project vulnerability CVSS: 5.0 06 Feb 2014, 05:44 UTC

Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.

CVE-2013-5611 opensuse_project vulnerability CVSS: 5.8 11 Dec 2013, 15:55 UTC

Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.

CVE-2012-0867 opensuse_project vulnerability CVSS: 4.3 18 Jul 2012, 23:55 UTC

PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.