Suse

Package Hub

40 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.29%
  • Published 16.10.2024 14:15:05
  • Last modified 16.10.2024 16:38:14

The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command in later steps

Exploit
  • EPSS 1.71%
  • Published 19.08.2020 15:15:12
  • Last modified 21.11.2024 05:14:40

Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v...

  • EPSS 3.55%
  • Published 22.03.2020 05:15:11
  • Last modified 21.11.2024 04:56:06

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Displa...

  • EPSS 1.62%
  • Published 22.03.2020 05:15:11
  • Last modified 21.11.2024 04:56:06

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSe...

  • EPSS 2.44%
  • Published 22.03.2020 04:15:11
  • Last modified 21.11.2024 04:56:06

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the...

Exploit
  • EPSS 3.87%
  • Published 11.02.2020 15:15:14
  • Last modified 21.11.2024 05:35:41

Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 2.9%
  • Published 11.02.2020 15:15:14
  • Last modified 21.11.2024 05:35:41

Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 1.74%
  • Published 11.02.2020 15:15:13
  • Last modified 21.11.2024 05:35:39

Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 1.37%
  • Published 11.02.2020 15:15:13
  • Last modified 21.11.2024 05:35:38

Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

Exploit
  • EPSS 1.37%
  • Published 11.02.2020 15:15:13
  • Last modified 21.11.2024 05:35:38

Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.