目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1310 CNY

100%

SUSE 厂商漏洞列表 / CVE 中文分析 190

SUSE 厂商相关 190 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

SUSE 主要提供企业级 Linux 操作系统及云原生解决方案,其核心产品涵盖 SUSE Linux Enterprise Server 等。历史漏洞多涉及远程代码执行、权限提升及缓冲区溢出,常源于内核组件或管理工具配置不当。值得关注的是,SUSE 定期发布安全更新以修复高危风险,并支持 OpenSUSE 社区版推动漏洞透明化。截至最新统计,已收录 185 条 CVE,反映其庞大生态中持续的安全维护需求。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-41054 Missing exit out of permission check in haveged could lead to root exploit — Container suse/sle-micro-rancher/5.3:latestCWE-305 7.8 High2026-05-20
CVE-2026-44933 Path Traversal in Plugin Loading in libzypp — SUSE Linux EnterpriseCWE-35 7.8 High2026-05-20
CVE-2026-41051 csync2 uses insecure temporary directories when compiled with C99 or later — openSUSE Tumbleweed 5.0 Medium2026-05-13
CVE-2026-41050 Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering — RancherCWE-863 9.9 Critical2026-05-13
CVE-2026-25705 Rancher Extensions have arbitrary file access via path traversal — rancherCWE-35 8.4 High2026-05-13
CVE-2026-25702 nftables disabled due to incorrect kernel backport — SUSE Linux Enterprise ServerCWE-284 7.3 High2026-03-05
CVE-2025-62879 Rancher Backup Operator pod's logs leak S3 tokens — RancherCWE-532 6.8 Medium2026-03-04
CVE-2025-62878 Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern — RancherCWE-23 9.9 Critical2026-02-25
CVE-2025-67601 Rancher CLI skips TLS verification on Rancher CLI login command — rancherCWE-295 8.3 High2026-02-25
CVE-2025-67860 NeuVector scanner insecurely handles passwords as command arguments — harvesterCWE-522 3.8 Low2026-02-25
CVE-2025-62877 Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer — harvesterCWE-1188 9.8 Critical2026-01-08
CVE-2025-66001 NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM) — neuvectorCWE-295 8.8 High2026-01-08
CVE-2025-62875 Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock — openSUSE TumbleweedCWE-754 5.5 -2025-11-20
CVE-2025-62876 LightDM KDE Greeter 安全漏洞 — openSUSECWE-250 7.8 -2025-11-12
CVE-2025-53883 spacewalk-java has various XSS issues on search page — Container suse manager 5.0CWE-80 6.1AIMediumAI2025-10-30
CVE-2025-53880 susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversal — Container suse/manager/4.3/proxy-httpd:latestCWE-35 6.5AIMediumAI2025-10-30
CVE-2025-54471 NeuVector is shipping cryptographic material into its binary — neuvectorCWE-321 6.5 Medium2025-10-30
CVE-2025-54469 NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow — neuvectorCWE-78 9.9 Critical2025-10-30
CVE-2025-54470 NeuVector telemetry sender is vulnerable to MITM and DoS — neuvectorCWE-295 8.6 High2025-10-30
CVE-2024-58269 Rancher exposes sensitive information through audit logs — rancherCWE-532 4.3 Medium2025-10-29
CVE-2023-32199 Rancher user retains access to clusters despite Global Role removal — rancherCWE-281 4.3 Medium2025-10-29
CVE-2024-58260 Rancher update on users can deny the service to the admin — rancherCWE-863 7.6 High2025-10-02
CVE-2024-58267 Rancher CLI SAML authentication is vulnerable to phishing attacks — rancherCWE-345 8.0 High2025-10-02
CVE-2025-54468 Rancher sends sensitive information to external services through the `/meta/proxy` endpoint — rancherCWE-200 4.7 Medium2025-10-02
CVE-2025-8077 NeuVector admin account has insecure default password — neuvectorCWE-1393 9.8 Critical2025-09-17
CVE-2025-54467 NeuVector process with sensitive arguments lead to leakage — neuvectorCWE-522 5.3 Medium2025-09-17
CVE-2025-53884 NeuVector has an insecure password storage vulnerable to rainbow attack — neuvectorCWE-759 5.3 Medium2025-09-17
CVE-2024-58259 Rancher affected by unauthenticated Denial of Service — rancherCWE-770 8.2 High2025-09-02
CVE-2024-52284 Rancher Fleet Helm Values are stored inside BundleDeployment in plain text — RancherCWE-312 7.7 High2025-09-02
CVE-2025-46809 Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logs — Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1CWE-256 5.7 Medium2025-07-31

本页汇总了 SUSE 厂商截至目前公开的全部 190 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。