By weakness (CWE)

CWE-24: related vulnerabilities

CVEs classified under CWE-24. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2026-44942MEDIUM 6.5

    A vulnerability in libzypp, the package management library used by openSUSE and other Linux distributions, allows an authenticated attacker to write files to arbitrary directories on a system by exploiting how the software processes repository configuration files (.repo files). Rather than storing downloaded content in the intended cache directories, an attacker could direct files to other locations on disk, potentially filling up storage or overwriting important system files. The issue affects libzypp versions before 17.38.13 in the 17.x branch and before 16.22.19 in the 16.x branch.