Opensuse

Leap

1897 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 02.09.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:15:23

In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.

  • EPSS 0.21%
  • Veröffentlicht 02.09.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:06:13

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...

  • EPSS 0.25%
  • Veröffentlicht 02.09.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:06:13

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...

  • EPSS 11.3%
  • Veröffentlicht 31.08.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:03:05

An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_tok...

  • EPSS 1.25%
  • Veröffentlicht 31.08.2020 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:16:42

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

  • EPSS 4.04%
  • Veröffentlicht 30.08.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:03:04

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the...

Exploit
  • EPSS 20.71%
  • Veröffentlicht 29.08.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:16:15

The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line opti...

  • EPSS 6.4%
  • Veröffentlicht 25.08.2020 14:15:16
  • Zuletzt bearbeitet 21.11.2024 05:15:09

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.

  • EPSS 6.34%
  • Veröffentlicht 24.08.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 05:15:08

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digest...

  • EPSS 0.69%
  • Veröffentlicht 24.08.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:03:04

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to exe...