Opensuse

Leap

1897 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.82%
  • Veröffentlicht 22.05.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:56:44

In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connections and the client adds another request in via HTTP...

  • EPSS 0.19%
  • Veröffentlicht 21.05.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:05

Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.

  • EPSS 0.7%
  • Veröffentlicht 21.05.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:40

An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.

  • EPSS 0.97%
  • Veröffentlicht 21.05.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:40

An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.

  • EPSS 0.77%
  • Veröffentlicht 21.05.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:40

An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.

  • EPSS 0.69%
  • Veröffentlicht 21.05.2020 04:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:49

Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 21.05.2020 04:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:49

Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

Exploit
  • EPSS 1.04%
  • Veröffentlicht 21.05.2020 04:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:49

Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted...

  • EPSS 1.04%
  • Veröffentlicht 21.05.2020 04:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:49

Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.

  • EPSS 0.91%
  • Veröffentlicht 21.05.2020 04:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:50

Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.