Opensuse

Leap

1898 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.5%
  • Veröffentlicht 02.08.2019 12:15:12
  • Zuletzt bearbeitet 21.11.2024 04:26:53

An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 01.08.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:26:51

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

  • EPSS 0.39%
  • Veröffentlicht 31.07.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:18:35

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be e...

  • EPSS 1.82%
  • Veröffentlicht 31.07.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:18:36

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the ...

  • EPSS 0.97%
  • Veröffentlicht 31.07.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:15

An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image t...

  • EPSS 0.97%
  • Veröffentlicht 31.07.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:15

An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image t...

  • EPSS 0.97%
  • Veröffentlicht 31.07.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:16

An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bou...

Exploit
  • EPSS 1.32%
  • Veröffentlicht 31.07.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:16

An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then ...

  • EPSS 0.01%
  • Veröffentlicht 30.07.2019 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:33

A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fac...

  • EPSS 0.01%
  • Veröffentlicht 30.07.2019 23:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:33

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIF...