Suse

Studio Onsite

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.5%
  • Veröffentlicht 26.05.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

  • EPSS 0.59%
  • Veröffentlicht 23.07.2015 00:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspec...

Warnung Exploit
  • EPSS 89.61%
  • Veröffentlicht 25.09.2014 01:55:04
  • Zuletzt bearbeitet 22.10.2025 01:16:04

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...

Warnung Exploit
  • EPSS 94.22%
  • Veröffentlicht 24.09.2014 18:48:04
  • Zuletzt bearbeitet 22.10.2025 01:15:57

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...

Exploit
  • EPSS 1.32%
  • Veröffentlicht 16.04.2014 18:37:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.

  • EPSS 0.26%
  • Veröffentlicht 16.04.2014 18:37:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted application,...

  • EPSS 0.5%
  • Veröffentlicht 16.04.2014 18:37:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."

Exploit
  • EPSS 1.49%
  • Veröffentlicht 16.04.2014 18:37:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

  • EPSS 0.33%
  • Veröffentlicht 26.02.2014 15:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 23.12.2013 23:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.