Suse

Package Hub

40 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.89%
  • Published 11.02.2020 15:15:12
  • Last modified 21.11.2024 05:35:37

Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 1.4%
  • Published 11.02.2020 15:15:12
  • Last modified 21.11.2024 05:35:37

Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.

Exploit
  • EPSS 2.9%
  • Published 11.02.2020 15:15:12
  • Last modified 21.11.2024 05:35:37

Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 2.9%
  • Published 11.02.2020 15:15:12
  • Last modified 21.11.2024 05:35:36

Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 0.32%
  • Published 04.02.2020 20:15:12
  • Last modified 21.11.2024 04:29:09

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

Exploit
  • EPSS 4.09%
  • Published 16.01.2020 04:15:11
  • Last modified 21.11.2024 05:36:38

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string fr...

  • EPSS 9.23%
  • Published 24.12.2019 17:15:10
  • Last modified 21.11.2024 04:35:40

zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

  • EPSS 10.52%
  • Published 24.12.2019 16:15:11
  • Last modified 21.11.2024 04:35:40

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

  • EPSS 8.34%
  • Published 23.12.2019 01:15:13
  • Last modified 21.11.2024 04:35:41

multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.

  • EPSS 8.44%
  • Published 18.12.2019 06:15:12
  • Last modified 21.11.2024 04:35:34

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.