Opensuse

Opensuse

1454 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Published 06.02.2014 05:44:24
  • Last modified 11.04.2025 00:51:21

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPosi...

  • EPSS 0.63%
  • Published 06.02.2014 05:44:24
  • Last modified 11.04.2025 00:51:21

Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.

  • EPSS 0.96%
  • Published 06.02.2014 05:44:24
  • Last modified 11.04.2025 00:51:21

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute a...

  • EPSS 10.82%
  • Published 06.02.2014 05:44:24
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unsp...

  • EPSS 0.97%
  • Published 05.02.2014 19:55:28
  • Last modified 11.04.2025 00:51:21

The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose orig...

Warning
  • EPSS 93.02%
  • Published 05.02.2014 05:15:29
  • Last modified 11.04.2025 00:51:21

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

Exploit
  • EPSS 0.61%
  • Published 04.02.2014 23:55:03
  • Last modified 11.04.2025 00:51:21

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

  • EPSS 0.09%
  • Published 04.02.2014 21:55:05
  • Last modified 11.04.2025 00:51:21

Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.

Exploit
  • EPSS 2.38%
  • Published 28.01.2014 14:30:39
  • Last modified 11.04.2025 00:51:21

The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other...

Exploit
  • EPSS 0.93%
  • Published 28.01.2014 14:30:33
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified oth...