Opensuse

Opensuse

1454 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warning Exploit
  • EPSS 94.48%
  • Published 07.04.2014 22:55:03
  • Last modified 12.04.2025 10:46:40

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...

  • EPSS 20.91%
  • Published 28.03.2014 15:55:08
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.

Exploit
  • EPSS 63.23%
  • Published 28.03.2014 15:55:08
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.

Exploit
  • EPSS 1.27%
  • Published 27.03.2014 16:55:05
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.8%
  • Published 25.03.2014 16:55:28
  • Last modified 12.04.2025 10:46:40

Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (1) display_nav_table, (2) print_export_link, (3) page_num_selector, or (4) page_limit_selec...

Exploit
  • EPSS 1.47%
  • Published 19.03.2014 10:55:06
  • Last modified 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and app...

  • EPSS 0.49%
  • Published 19.03.2014 10:55:06
  • Last modified 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via u...

Exploit
  • EPSS 0.5%
  • Published 19.03.2014 10:55:06
  • Last modified 12.04.2025 10:46:40

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause...

  • EPSS 0.55%
  • Published 19.03.2014 10:55:06
  • Last modified 12.04.2025 10:46:40

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger gene...

  • EPSS 0.61%
  • Published 19.03.2014 10:55:06
  • Last modified 12.04.2025 10:46:40

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.