Opensuse

Leap

1898 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 15.94%
  • Veröffentlicht 07.08.2016 10:59:20
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execu...

Exploit
  • EPSS 9.58%
  • Veröffentlicht 07.08.2016 10:59:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-a...

Exploit
  • EPSS 10.05%
  • Veröffentlicht 07.08.2016 10:59:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large inte...

  • EPSS 2.4%
  • Veröffentlicht 07.08.2016 10:59:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer ...

  • EPSS 0.32%
  • Veröffentlicht 02.08.2016 14:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpa...

  • EPSS 0.06%
  • Veröffentlicht 26.07.2016 17:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.

  • EPSS 3.69%
  • Veröffentlicht 23.07.2016 19:59:13
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

  • EPSS 60.28%
  • Veröffentlicht 19.07.2016 02:00:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an app...

  • EPSS 81.35%
  • Veröffentlicht 19.07.2016 02:00:17
  • Zuletzt bearbeitet 06.05.2026 22:30:45

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attacker...

  • EPSS 0.05%
  • Veröffentlicht 13.07.2016 15:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.