Opensuse

Opensuse

1454 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 13.98%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple...

  • EPSS 7.81%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.

  • EPSS 0.21%
  • Veröffentlicht 19.11.2013 04:50:56
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of s...

  • EPSS 5.86%
  • Veröffentlicht 18.11.2013 03:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon ...

Exploit
  • EPSS 1.45%
  • Veröffentlicht 18.11.2013 02:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and ...

Exploit
  • EPSS 1.48%
  • Veröffentlicht 13.11.2013 15:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.

Exploit
  • EPSS 2.91%
  • Veröffentlicht 08.11.2013 04:47:22
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 02.11.2013 19:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions.

Exploit
  • EPSS 22.61%
  • Veröffentlicht 28.10.2013 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large c...

Exploit
  • EPSS 6.43%
  • Veröffentlicht 26.10.2013 17:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory travers...