Opensuse

Leap

1897 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.63%
  • Published 18.12.2019 20:15:16
  • Last modified 13.02.2025 15:37:40

There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id....

  • EPSS 8.44%
  • Published 18.12.2019 06:15:12
  • Last modified 21.11.2024 04:35:34

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

  • EPSS 0.56%
  • Published 16.12.2019 20:15:15
  • Last modified 21.11.2024 04:31:10

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content ...

  • EPSS 0.29%
  • Published 13.12.2019 01:15:11
  • Last modified 21.11.2024 04:31:10

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and cre...

  • EPSS 0.35%
  • Published 13.12.2019 01:15:10
  • Last modified 21.11.2024 04:31:09

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the ...

  • EPSS 0.4%
  • Published 13.12.2019 01:15:10
  • Last modified 21.11.2024 04:31:10

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field wou...

Exploit
  • EPSS 2.42%
  • Published 12.12.2019 14:15:16
  • Last modified 21.11.2024 04:32:10

Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti ...

  • EPSS 2.07%
  • Published 11.12.2019 18:16:19
  • Last modified 21.11.2024 04:34:59

An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA...

Exploit
  • EPSS 1.34%
  • Published 11.12.2019 00:15:13
  • Last modified 21.11.2024 04:35:02

Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a ma...

  • EPSS 1.65%
  • Published 10.12.2019 23:15:10
  • Last modified 21.11.2024 04:27:31

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stor...