Opensuse

Leap

1897 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.53%
  • Published 27.03.2020 20:15:11
  • Last modified 21.11.2024 05:35:05

An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send...

  • EPSS 0.7%
  • Published 27.03.2020 13:15:15
  • Last modified 21.11.2024 05:11:21

In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. ...

  • EPSS 0.36%
  • Published 27.03.2020 13:15:15
  • Last modified 21.11.2024 05:11:21

Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

  • EPSS 0.59%
  • Published 27.03.2020 13:15:15
  • Last modified 21.11.2024 05:11:21

It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and pri...

Exploit
  • EPSS 0.04%
  • Published 24.03.2020 22:15:12
  • Last modified 21.11.2024 04:56:25

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

  • EPSS 1.68%
  • Published 24.03.2020 16:15:12
  • Last modified 21.11.2024 04:56:24

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

  • EPSS 2.59%
  • Published 24.03.2020 15:15:12
  • Last modified 21.11.2024 05:11:17

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that us...

  • EPSS 1.22%
  • Published 23.03.2020 13:15:13
  • Last modified 21.11.2024 04:55:39

Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negoti...

  • EPSS 2%
  • Published 23.03.2020 13:15:12
  • Last modified 21.11.2024 04:55:39

Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.

  • EPSS 1.62%
  • Published 22.03.2020 05:15:11
  • Last modified 21.11.2024 04:56:06

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSe...