Opensuse

Leap

1897 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Veröffentlicht 14.10.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:36

There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

  • EPSS 2.39%
  • Veröffentlicht 14.10.2019 02:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:29

GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

Exploit
  • EPSS 7.08%
  • Veröffentlicht 10.10.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:21

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a craf...

Exploit
  • EPSS 1.09%
  • Veröffentlicht 10.10.2019 17:15:17
  • Zuletzt bearbeitet 21.11.2024 04:32:20

find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.

Exploit
  • EPSS 0.82%
  • Veröffentlicht 10.10.2019 17:15:17
  • Zuletzt bearbeitet 21.11.2024 04:32:20

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

  • EPSS 0.14%
  • Veröffentlicht 08.10.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:29

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBU...

  • EPSS 1.02%
  • Veröffentlicht 07.10.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:34

An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to a...

  • EPSS 0.37%
  • Veröffentlicht 07.10.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:35

An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account fo...

  • EPSS 0.87%
  • Veröffentlicht 04.10.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:48

libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.

  • EPSS 0.83%
  • Veröffentlicht 04.10.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:48

HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return v...