Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.89%
  • Veröffentlicht 20.02.2014 15:27:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML ...

  • EPSS 0.64%
  • Veröffentlicht 10.02.2014 18:15:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user a...

  • EPSS 0.43%
  • Veröffentlicht 10.02.2014 18:15:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user i...

  • EPSS 0.63%
  • Veröffentlicht 10.02.2014 18:15:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash c...

  • EPSS 0.25%
  • Veröffentlicht 08.02.2014 00:55:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.

  • EPSS 8.06%
  • Veröffentlicht 06.02.2014 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML docum...

Exploit
  • EPSS 57.68%
  • Veröffentlicht 06.02.2014 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.

  • EPSS 0.51%
  • Veröffentlicht 06.02.2014 17:00:03
  • Zuletzt bearbeitet 09.06.2025 15:15:22

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

  • EPSS 0.41%
  • Veröffentlicht 06.02.2014 17:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 06.02.2014 05:44:25
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information v...