Opensuse

Leap

1897 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.61%
  • Published 03.06.2020 23:15:11
  • Last modified 21.11.2024 05:35:50

Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • EPSS 0.5%
  • Published 03.06.2020 23:15:11
  • Last modified 21.11.2024 05:35:50

Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • EPSS 0.52%
  • Published 03.06.2020 23:15:11
  • Last modified 21.11.2024 05:35:50

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • EPSS 1.34%
  • Published 03.06.2020 23:15:11
  • Last modified 21.11.2024 05:35:50

Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

Exploit
  • EPSS 92.95%
  • Published 03.06.2020 19:15:10
  • Last modified 21.11.2024 05:01:08

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can b...

  • EPSS 0.07%
  • Published 03.06.2020 00:15:10
  • Last modified 21.11.2024 04:39:25

go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.

  • EPSS 0.03%
  • Published 02.06.2020 13:15:11
  • Last modified 21.11.2024 05:01:42

address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.

Exploit
  • EPSS 0.11%
  • Published 01.06.2020 14:15:10
  • Last modified 21.11.2024 05:00:27

A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.

  • EPSS 0.23%
  • Published 29.05.2020 20:15:11
  • Last modified 21.11.2024 04:56:45

In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1...

  • EPSS 0.12%
  • Published 29.05.2020 20:15:10
  • Last modified 21.11.2024 04:56:39

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_decompress_subcode_rlex, visualized on screen as color. This has been patched in 2.1.0.