Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.93%
  • Veröffentlicht 26.08.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527...

  • EPSS 0.98%
  • Veröffentlicht 25.08.2014 14:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

  • EPSS 0.07%
  • Veröffentlicht 22.08.2014 14:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking thes...

  • EPSS 0.07%
  • Veröffentlicht 22.08.2014 14:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page a...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 22.08.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new h...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 22.08.2014 01:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/function...

  • EPSS 0.16%
  • Veröffentlicht 20.08.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.

  • EPSS 2.62%
  • Veröffentlicht 19.08.2014 18:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to ...

  • EPSS 4.78%
  • Veröffentlicht 19.08.2014 18:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authenticat...

Medienbericht
  • EPSS 2.09%
  • Veröffentlicht 07.08.2014 11:13:34
  • Zuletzt bearbeitet 12.04.2025 10:46:40

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.