Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.29%
  • Veröffentlicht 29.12.2014 00:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.

  • EPSS 0.13%
  • Veröffentlicht 19.12.2014 15:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

  • EPSS 0.47%
  • Veröffentlicht 16.12.2014 23:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via...

  • EPSS 2.09%
  • Veröffentlicht 16.12.2014 18:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 12.12.2014 18:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted ...

  • EPSS 0.78%
  • Veröffentlicht 12.12.2014 15:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests...

  • EPSS 0.04%
  • Veröffentlicht 09.12.2014 23:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read...

  • EPSS 0.07%
  • Veröffentlicht 09.12.2014 23:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a dif...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 08.12.2014 16:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 08.12.2014 11:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, ...