Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 26.01.2009 15:30:04
  • Zuletzt bearbeitet 09.04.2025 00:30:58

fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, l...

  • EPSS 1.97%
  • Veröffentlicht 21.11.2008 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggere...

  • EPSS 25.26%
  • Veröffentlicht 13.11.2008 11:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying pr...

  • EPSS 0.39%
  • Veröffentlicht 13.11.2008 01:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers t...

  • EPSS 1.1%
  • Veröffentlicht 15.10.2008 20:08:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.09.2008 17:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.

  • EPSS 0.09%
  • Veröffentlicht 08.08.2008 19:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different for...

  • EPSS 67.24%
  • Veröffentlicht 06.08.2008 18:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary we...

  • EPSS 0.71%
  • Veröffentlicht 22.07.2008 16:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.

  • EPSS 0.02%
  • Veröffentlicht 09.07.2008 18:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of ...