Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 26.11.2010 19:00:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kerne...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 22.11.2010 13:00:19
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small v...

  • EPSS 0.05%
  • Veröffentlicht 22.11.2010 13:00:19
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.

  • EPSS 4.32%
  • Veröffentlicht 22.11.2010 13:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP ...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 17.11.2010 01:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to ca...

  • EPSS 3.86%
  • Veröffentlicht 05.11.2010 18:00:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unkn...

  • EPSS 27.69%
  • Veröffentlicht 05.11.2010 17:00:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbi...

Exploit
  • EPSS 1.95%
  • Veröffentlicht 21.10.2010 19:00:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "stale elements."

Exploit
  • EPSS 0.6%
  • Veröffentlicht 21.10.2010 19:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.

  • EPSS 0.04%
  • Veröffentlicht 12.10.2010 20:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple buffer overflows in the Novell Client novfs module for the Linux kernel in SUSE Linux Enterprise 11 SP1 and openSUSE 11.3 allow local users to gain privileges via unspecified vectors.