Opensuse

Leap

1897 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 23.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:11

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESO...

  • EPSS 0.03%
  • Veröffentlicht 23.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:11

An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.

  • EPSS 0.03%
  • Veröffentlicht 23.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:11

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.

Exploit
  • EPSS 35.84%
  • Veröffentlicht 23.12.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:26

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications check...

  • EPSS 7.89%
  • Veröffentlicht 23.12.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:26

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are ide...

Exploit
  • EPSS 3.12%
  • Veröffentlicht 23.12.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:27

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocate...

  • EPSS 8.34%
  • Veröffentlicht 23.12.2019 01:15:13
  • Zuletzt bearbeitet 21.11.2024 04:35:41

multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 20.12.2019 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:39

Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 20.12.2019 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:39

Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

  • EPSS 53.46%
  • Veröffentlicht 20.12.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:33

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic fo...