Opensuse

Leap

1898 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.33%
  • Veröffentlicht 07.11.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:25

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using ...

Exploit
  • EPSS 58.17%
  • Veröffentlicht 07.11.2018 05:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:14

An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 21.10.2018 01:29:00
  • Zuletzt bearbeitet 21.11.2024 03:56:07

There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.

Exploit
  • EPSS 0.89%
  • Veröffentlicht 19.10.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:56:05

An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entrie...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 19.10.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:56:05

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize i...

  • EPSS 0.65%
  • Veröffentlicht 15.10.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:28:42

Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 15.10.2018 02:29:00
  • Zuletzt bearbeitet 21.11.2024 03:55:40

An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated b...

  • EPSS 1.18%
  • Veröffentlicht 12.10.2018 06:29:00
  • Zuletzt bearbeitet 21.11.2024 03:55:33

In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 09.10.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 03:55:26

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

  • EPSS 0.32%
  • Veröffentlicht 09.10.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:17

A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versio...