CRITICAL9.8CVE-2017-9269In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to sil… from 0, < 17.3.1-1
HIGH8.8CVE-2026-44941A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply… from 0
HIGH8.8A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supp…
from 0
HIGH8.1In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middl…
from 0, < 17.3.1-1
HIGH8.1In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middl…
from 0, < 17.3.1-1
HIGH7.8The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later…
from 0, < 17.6.1-1
MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.1…
from 0
LOW3.3libzypp - security update
from 0, < 17.25.5-2
LOW3.3libzypp - security update
from 0, < 14.29.1-2+deb8u1
LOW3.3The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxi…
from 0, < 17.25.5-2