Opensuse

Leap

1898 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 18.08.2019 19:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:08

WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirect...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 18.08.2019 19:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:08

In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.

Exploit
  • EPSS 0.88%
  • Veröffentlicht 18.08.2019 19:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:09

In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 18.08.2019 19:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:09

In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h...

  • EPSS 0.13%
  • Veröffentlicht 16.08.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:28:05

check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.

  • EPSS 0.16%
  • Veröffentlicht 16.08.2019 02:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:02

drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

  • EPSS 0.11%
  • Veröffentlicht 16.08.2019 00:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:02

An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.

  • EPSS 2.91%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify tha...

  • EPSS 85.78%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calli...

  • EPSS 0.11%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...