[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fw1nQEOaxg3nhYufP7lpY9OyS5_XGAItw7sZPGysYeq0":3},{"product":4,"cycleMajor":14,"releases":15,"cves":28,"nextMajor":96,"indexable":55},{"id":5,"slug":6,"name":7,"category":8,"vendor":9,"description":10,"logo_url":11,"official_url":9,"synced_at":12,"created_at":13},"631d2164-d631-4ae7-8e0b-cbf66b8f6295","opensuse","Opensuse","os",null,"Developers rely on Opensuse, an operating system that has been around since 2005, to power their applications and systems, and it is maintained by the openSUSE Project community. The community-driven approach ensures that the operating system is shaped by the needs of its users, making it a popular choice among developers who value flexibility and customization. By tracking the end-of-life dates of Opensuse, developers can plan their upgrades and ensure that their systems remain secure and supported. This is particularly important in today's fast-paced technology landscape, where staying ahead of potential security vulnerabilities is crucial.\n\nThe end-of-life landscape for Opensuse is characterized by a large number of versions that have already reached their end-of-life, with 20 out of 21 versions no longer supported. The next version to expire is 16.0, which will reach its end-of-life on October 31, 2027. This gives developers a clear timeline to plan their upgrades and migrations to newer versions. The most recent version to reach its end-of-life was 15.6, which expired on April 30, 2026. With only one active version currently available, developers should be aware of the upcoming end-of-life dates to avoid any potential disruptions to their systems.\n\nGiven the current security landscape, Opensuse has a clean slate with no tracked CVEs, which is a testament to the community's efforts to maintain a secure operating system. As a result, there are no critical CVEs to report, and no version is particularly affected. Furthermore, with no known vulnerabilities, the KEV status is not applicable. Despite this positive security picture, developers should still prioritize staying up-to-date with the latest versions and security patches to ensure the continued security and integrity of their systems. By doing so, they can take proactive measures to protect their applications and data from potential threats.","https:\u002F\u002Fcdn.simpleicons.org\u002Fopensuse","2026-10-07T02:00:12.129+00:00","2026-05-30T16:23:55.904463+00:00","13",[16,23],{"id":17,"product_id":5,"cycle":18,"release_date":19,"eol":20,"eol_boolean":9,"latest":9,"latest_release_date":9,"lts":21,"support":9,"created_at":22},"ab4a7454-24a8-4c44-90f7-a95f02fba666","13.2","2014-11-04","2017-01-17",false,"2026-05-30T16:26:03.501267+00:00",{"id":24,"product_id":5,"cycle":25,"release_date":26,"eol":27,"eol_boolean":9,"latest":9,"latest_release_date":9,"lts":21,"support":9,"created_at":22},"9168174f-637e-4002-8680-ebea30099a88","13.1","2014-01-08","2016-02-03",[29,37,45,51,58,59,67,73,80,88,89],{"cveId":30,"releaseId":17,"cycle":18,"description":31,"severity":32,"cvssScore":33,"epssScore":34,"inKev":21,"publishedAt":35,"url":36},"CVE-2016-9842","The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.","HIGH",8.8,0.05204,"2017-05-23T04:29:01.837+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2016-9842",{"cveId":38,"releaseId":17,"cycle":18,"description":39,"severity":40,"cvssScore":41,"epssScore":42,"inKev":21,"publishedAt":43,"url":44},"CVE-2016-9841","inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.","CRITICAL",9.8,0.0755,"2017-05-23T04:29:01.743+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2016-9841",{"cveId":46,"releaseId":17,"cycle":18,"description":47,"severity":32,"cvssScore":33,"epssScore":48,"inKev":21,"publishedAt":49,"url":50},"CVE-2016-9840","inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.",0.04793,"2017-05-23T04:29:01.667+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2016-9840",{"cveId":52,"releaseId":24,"cycle":25,"description":53,"severity":40,"cvssScore":41,"epssScore":54,"inKev":55,"publishedAt":56,"url":57},"CVE-2016-4117","Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.",0.94354,true,"2016-05-11T01:59:46.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2016-4117",{"cveId":52,"releaseId":17,"cycle":18,"description":53,"severity":40,"cvssScore":41,"epssScore":54,"inKev":55,"publishedAt":56,"url":57},{"cveId":60,"releaseId":17,"cycle":18,"description":61,"severity":62,"cvssScore":63,"epssScore":64,"inKev":21,"publishedAt":65,"url":66},"CVE-2015-8036","Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a ClientHello message to resume a session.  NOTE: this identifier was SPLIT from CVE-2015-5291 per ADT3 due to different affected version ranges.","MEDIUM",6.8,0.0289,"2015-11-02T19:59:16.267+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2015-8036",{"cveId":68,"releaseId":17,"cycle":18,"description":69,"severity":62,"cvssScore":63,"epssScore":70,"inKev":21,"publishedAt":71,"url":72},"CVE-2015-5291","Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a ClientHello message.  NOTE: this identifier has been SPLIT per ADT3 due to different affected version ranges. See CVE-2015-8036 for the session ti",0.03659,"2015-11-02T19:59:05.123+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2015-5291",{"cveId":74,"releaseId":17,"cycle":18,"description":75,"severity":62,"cvssScore":76,"epssScore":77,"inKev":55,"publishedAt":78,"url":79},"CVE-2015-3246","libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies \u002Fetc\u002Fpasswd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.",5.1,0.08434,"2015-08-11T14:59:07.04+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2015-3246",{"cveId":81,"releaseId":24,"cycle":25,"description":82,"severity":83,"cvssScore":84,"epssScore":85,"inKev":21,"publishedAt":86,"url":87},"CVE-2015-2808","The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the \"Bar Mitzvah\" issue.","LOW",3.7,0.73851,"2015-04-01T02:00:35.097+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2015-2808",{"cveId":81,"releaseId":17,"cycle":18,"description":82,"severity":83,"cvssScore":84,"epssScore":85,"inKev":21,"publishedAt":86,"url":87},{"cveId":90,"releaseId":24,"cycle":25,"description":91,"severity":83,"cvssScore":92,"epssScore":93,"inKev":21,"publishedAt":94,"url":95},"CVE-2014-3566","The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the \"POODLE\" issue.",3.4,0.99999,"2014-10-15T00:55:02.137+00:00","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2014-3566","15"]