Opensuse

Leap

1898 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 53.59%
  • Veröffentlicht 09.03.2016 23:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

  • EPSS 68.97%
  • Veröffentlicht 09.03.2016 23:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed...

  • EPSS 1.2%
  • Veröffentlicht 23.02.2016 19:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown...

  • EPSS 11.88%
  • Veröffentlicht 23.02.2016 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.

  • EPSS 12.34%
  • Veröffentlicht 23.02.2016 19:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown...

  • EPSS 3.21%
  • Veröffentlicht 21.02.2016 18:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.

  • EPSS 0.39%
  • Veröffentlicht 20.02.2016 01:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the ...

  • EPSS 0.58%
  • Veröffentlicht 20.02.2016 01:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path ...

  • EPSS 1.03%
  • Veröffentlicht 20.02.2016 01:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restri...

  • EPSS 0.49%
  • Veröffentlicht 20.02.2016 01:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) s...