Opensuse

Leap

1897 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 30.07.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:58

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further ca...

  • EPSS 0.04%
  • Veröffentlicht 29.07.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:02:58

In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integri...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 29.07.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:06:47

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

  • EPSS 0.03%
  • Veröffentlicht 29.07.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:06:03

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB imag...

  • EPSS 0.06%
  • Veröffentlicht 29.07.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:06:03

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure b...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 29.07.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:06:04

Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffe...

  • EPSS 12.14%
  • Veröffentlicht 28.07.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:06:24

A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and...

  • EPSS 0.26%
  • Veröffentlicht 27.07.2020 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:04:48

In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindl...

  • EPSS 2.24%
  • Veröffentlicht 23.07.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:06:26

common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

  • EPSS 3.23%
  • Veröffentlicht 22.07.2020 17:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:53

Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.