Suse

Linux Enterprise

97 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 12.04.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 12.04.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.

  • EPSS 0.74%
  • Veröffentlicht 03.02.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

  • EPSS 0.64%
  • Veröffentlicht 03.02.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

  • EPSS 0.39%
  • Veröffentlicht 23.12.2016 22:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which gre...

  • EPSS 0.7%
  • Veröffentlicht 10.10.2016 16:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to ...

  • EPSS 0.33%
  • Veröffentlicht 10.10.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response s...

  • EPSS 3.87%
  • Veröffentlicht 23.07.2016 19:59:13
  • Zuletzt bearbeitet 04.12.2025 17:15:49

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

  • EPSS 0.28%
  • Veröffentlicht 20.06.2016 01:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.

  • EPSS 1%
  • Veröffentlicht 05.06.2016 23:59:33
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.