Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.31%
  • Veröffentlicht 13.04.2016 14:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to execute arbitrary commands via a service definition, related to executing unzip w...

  • EPSS 1.39%
  • Veröffentlicht 11.04.2016 21:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese ch...

  • EPSS 18.02%
  • Veröffentlicht 08.04.2016 15:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

  • EPSS 0.13%
  • Veröffentlicht 08.04.2016 15:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Lin...

  • EPSS 35.46%
  • Veröffentlicht 08.04.2016 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.

  • EPSS 25.72%
  • Veröffentlicht 08.04.2016 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.

Exploit
  • EPSS 23.06%
  • Veröffentlicht 07.04.2016 23:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-...

  • EPSS 0.8%
  • Veröffentlicht 07.04.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

  • EPSS 1.37%
  • Veröffentlicht 05.04.2016 20:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecif...

  • EPSS 0.85%
  • Veröffentlicht 29.03.2016 10:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.