← Vulnerability feed

Vulnerability record · CVE-2021-36781 · published 14 January 2022

CVE-2021-36781: Opensuse factory incorrect default permissions vulnerability

Opensuse · Factory

A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.

4.4 CVSS 3.1 Medium EPSS 0.21% · top 90.3% CWE-276 · Incorrect default permissions
4.4CVSS 3.1 base score, v2 3.6
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.suse.com/show_bug.cgi?id=1193484 ExploitIssue TrackingPatchThird Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1193484 ExploitIssue TrackingPatchThird Party Advisory

Track CVE-2021-36781 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-31256Opensuse factory link following vulnerabilityA Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory…EPSS 0.24%7.8CVE-2021-45082Cobbler project cobbler command injection vulnerabilityAn issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Pyth…EPSS 0.50%7.8CVE-2021-25319Opensuse factory incorrect default permissions vulnerabilityA Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to es…EPSS 0.26%7.5CVE-2021-41819Ruby-lang cgi reliance on cookies without validation vulnerabilityCGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.EPSS 2.9%7.5CVE-2021-41817Ruby-lang date inefficient regular expression (redos) vulnerabilityDate.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1…EPSS 3.2%7.1CVE-2021-4166Vim out-of-bounds read vulnerabilityvim is vulnerable to Out-of-bounds ReadEPSS 1.6%6.3CVE-2022-31251Opensuse factory incorrect default permissions vulnerabilityA Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over th…EPSS 0.21%5.5CVE-2021-46141Uriparser project uriparser use after free vulnerabilityAn issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2021-36781), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.