Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung
  • EPSS 90.51%
  • Veröffentlicht 13.01.2010 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMe...

  • EPSS 12.31%
  • Veröffentlicht 09.01.2010 18:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) requ...

  • EPSS 0.3%
  • Veröffentlicht 08.01.2010 17:30:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.

Warnung Exploit
  • EPSS 92.89%
  • Veröffentlicht 15.12.2009 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZL...

  • EPSS 0.07%
  • Veröffentlicht 20.11.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.11.2009 19:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.

  • EPSS 2.15%
  • Veröffentlicht 13.11.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight,...

Exploit
  • EPSS 3.44%
  • Veröffentlicht 04.11.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...

  • EPSS 0.02%
  • Veröffentlicht 23.10.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that ha...

  • EPSS 0.07%
  • Veröffentlicht 22.10.2009 16:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...