Opensuse

Leap

1897 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 23.09.2020 22:15:13
  • Last modified 21.11.2024 05:18:13

An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also o...

  • EPSS 0.12%
  • Published 23.09.2020 21:15:12
  • Last modified 21.11.2024 05:18:11

An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strict...

  • EPSS 0.66%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:58

Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.

  • EPSS 0.86%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:58

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • EPSS 0.89%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:58

Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • EPSS 0.53%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:58

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • EPSS 0.53%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:58

Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

Exploit
  • EPSS 1.17%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:58

Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 0.91%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:58

Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.

Exploit
  • EPSS 0.96%
  • Published 21.09.2020 20:15:15
  • Last modified 21.11.2024 05:35:59

Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.