Opensuse

Opensuse

1454 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.89%
  • Published 20.02.2014 15:27:09
  • Last modified 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML ...

  • EPSS 0.64%
  • Published 10.02.2014 18:15:09
  • Last modified 11.04.2025 00:51:21

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user a...

  • EPSS 0.43%
  • Published 10.02.2014 18:15:09
  • Last modified 11.04.2025 00:51:21

Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user i...

  • EPSS 0.63%
  • Published 10.02.2014 18:15:09
  • Last modified 11.04.2025 00:51:21

internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash c...

  • EPSS 0.25%
  • Published 08.02.2014 00:55:06
  • Last modified 11.04.2025 00:51:21

python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.

  • EPSS 8.06%
  • Published 06.02.2014 22:55:03
  • Last modified 11.04.2025 00:51:21

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML docum...

Exploit
  • EPSS 57.68%
  • Published 06.02.2014 22:55:03
  • Last modified 11.04.2025 00:51:21

The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.

  • EPSS 0.51%
  • Published 06.02.2014 17:00:03
  • Last modified 09.06.2025 15:15:22

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

  • EPSS 0.41%
  • Published 06.02.2014 17:00:03
  • Last modified 11.04.2025 00:51:21

osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.

Exploit
  • EPSS 0.5%
  • Published 06.02.2014 05:44:25
  • Last modified 11.04.2025 00:51:21

The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information v...