CVE-2016-0718
- EPSS 1.5%
- Veröffentlicht 26.05.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
CVE-2015-1283
- EPSS 0.59%
- Veröffentlicht 23.07.2015 00:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspec...
- EPSS 89.61%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 22.10.2025 01:16:04
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 22.10.2025 01:15:57
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2011-4195
- EPSS 1.32%
- Veröffentlicht 16.04.2014 18:37:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.
CVE-2011-4193
- EPSS 0.26%
- Veröffentlicht 16.04.2014 18:37:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted application,...
CVE-2011-4192
- EPSS 0.5%
- Veröffentlicht 16.04.2014 18:37:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."
CVE-2011-3180
- EPSS 1.49%
- Veröffentlicht 16.04.2014 18:37:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.
- EPSS 0.33%
- Veröffentlicht 26.02.2014 15:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.
CVE-2013-3709
- EPSS 0.03%
- Veröffentlicht 23.12.2013 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.