Opensuse

Opensuse

1455 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 11.71%
  • Veröffentlicht 04.09.2014 17:55:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.

  • EPSS 5.72%
  • Veröffentlicht 03.09.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or...

  • EPSS 5.8%
  • Veröffentlicht 03.09.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of servi...

  • EPSS 5.47%
  • Veröffentlicht 03.09.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script ...

  • EPSS 1.76%
  • Veröffentlicht 27.08.2014 01:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated wi...

  • EPSS 2.64%
  • Veröffentlicht 27.08.2014 01:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging ...

  • EPSS 2.3%
  • Veröffentlicht 26.08.2014 14:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slas...

  • EPSS 2.47%
  • Veröffentlicht 26.08.2014 14:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is up...

  • EPSS 1.96%
  • Veröffentlicht 26.08.2014 14:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticat...

Exploit
  • EPSS 1.98%
  • Veröffentlicht 26.08.2014 14:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated use...