Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 06.02.2014 05:44:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPosi...

  • EPSS 0.63%
  • Veröffentlicht 06.02.2014 05:44:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.

  • EPSS 0.96%
  • Veröffentlicht 06.02.2014 05:44:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute a...

  • EPSS 10.82%
  • Veröffentlicht 06.02.2014 05:44:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unsp...

  • EPSS 0.97%
  • Veröffentlicht 05.02.2014 19:55:28
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose orig...

Warnung
  • EPSS 93.02%
  • Veröffentlicht 05.02.2014 05:15:29
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 04.02.2014 23:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

  • EPSS 0.09%
  • Veröffentlicht 04.02.2014 21:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.

Exploit
  • EPSS 2.38%
  • Veröffentlicht 28.01.2014 14:30:39
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other...

Exploit
  • EPSS 0.93%
  • Veröffentlicht 28.01.2014 14:30:33
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified oth...