Opensuse

Leap

1897 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.23%
  • Veröffentlicht 08.04.2019 19:29:05
  • Zuletzt bearbeitet 21.11.2024 04:20:20

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.

Exploit
  • EPSS 2.35%
  • Veröffentlicht 08.04.2019 19:29:05
  • Zuletzt bearbeitet 21.11.2024 04:20:20

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact ...

Exploit
  • EPSS 1.38%
  • Veröffentlicht 08.04.2019 19:29:05
  • Zuletzt bearbeitet 21.11.2024 04:20:21

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.

  • EPSS 0.64%
  • Veröffentlicht 08.04.2019 19:29:05
  • Zuletzt bearbeitet 21.11.2024 04:20:21

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.

Exploit
  • EPSS 2.57%
  • Veröffentlicht 08.04.2019 19:29:05
  • Zuletzt bearbeitet 21.11.2024 04:37:22

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected de...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 07.04.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:19:49

In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This ...

  • EPSS 2.62%
  • Veröffentlicht 07.04.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:06

In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 04.04.2019 16:29:03
  • Zuletzt bearbeitet 21.11.2024 04:42:47

An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causi...

  • EPSS 12.7%
  • Veröffentlicht 03.04.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 04:01:37

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to exe...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 01.04.2019 15:29:01
  • Zuletzt bearbeitet 21.11.2024 04:42:39

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.