Opensuse

Leap

1897 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.67%
  • Veröffentlicht 12.08.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:49

In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.

Exploit
  • EPSS 2.82%
  • Veröffentlicht 09.08.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:25

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past ...

Exploit
  • EPSS 3.29%
  • Veröffentlicht 09.08.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:25

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past ...

  • EPSS 0.22%
  • Veröffentlicht 09.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:27:23

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

  • EPSS 0.85%
  • Veröffentlicht 06.08.2019 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:11

Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.

  • EPSS 0.29%
  • Veröffentlicht 06.08.2019 19:15:13
  • Zuletzt bearbeitet 21.11.2024 04:24:11

In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.

  • EPSS 4.54%
  • Veröffentlicht 02.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:26:15

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid...

  • EPSS 3.63%
  • Veröffentlicht 02.08.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:15

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs...

  • EPSS 4.68%
  • Veröffentlicht 02.08.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:15

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large ...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 02.08.2019 12:15:12
  • Zuletzt bearbeitet 21.11.2024 04:26:53

An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.