← Back

Backports Sle

backports_sle

Vendor: Opensuse • 326 CVEs

CVEs (326)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Debian
FedoraprojectOpensuse+2 more
6Backports Sle
Debian LinuxFedora+3 more
Jun 17, 2026
Mar 22, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.ph...Show more
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.Show less
5Debian
FedoraprojectOpensuse+2 more
6Backports Sle
Debian LinuxFedora+3 more
Jun 17, 2026
Mar 22, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/cla...Show more
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.Show less
4Fedoraproject
OpensusePhpmyadmin+1 more
5Backports Sle
FedoraLeap+2 more
Jun 17, 2026
Mar 22, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A mal...Show more
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).Show less
3Debian
GraphicsmagickOpensuse
4Backports Sle
Debian LinuxGraphicsmagick+1 more
Jun 17, 2026
Mar 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
2Nagios
Opensuse
3Backports Sle
LeapNagios
Jun 17, 2026
Feb 28, 2020
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or p...Show more
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.Show less
3Fedoraproject
Openfortivpn ProjectOpensuse
4Backports Sle
FedoraLeap+1 more
Jun 17, 2026
Feb 27, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.examp...Show more
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.Show less
3Fedoraproject
Openfortivpn ProjectOpensuse
4Backports Sle
FedoraLeap+1 more
Jun 17, 2026
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid ce...Show more
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).Show less
3Fedoraproject
Openfortivpn ProjectOpensuse
4Backports Sle
FedoraLeap+1 more
Jun 17, 2026
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
5Debian
FedoraprojectOpensuse+2 more
7Backports Sle
Debian LinuxFedora+4 more
Jun 17, 2026
Feb 20, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
3Opensuse
ProftpdSiemens
5Backports Sle
LeapProftpd+2 more
Jun 17, 2026
Feb 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
4Debian
FedoraprojectOpensuse+1 more
5Backports Sle
Debian LinuxFedora+2 more
Jun 17, 2026
Feb 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malfor...Show more
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).Show less
6Debian
FedoraprojectGoogle+3 more
8Backports Sle
ChromeDebian Linux+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
6Debian
FedoraprojectGoogle+3 more
8Backports Sle
ChromeDebian Linux+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Feb 11, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
6Debian
FedoraprojectGoogle+3 more
8Backports Sle
ChromeDebian Linux+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
6Debian
FedoraprojectGoogle+3 more
8Backports Sle
ChromeDebian Linux+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
6Debian
FedoraprojectGoogle+3 more
8Backports Sle
ChromeDebian Linux+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
6Debian
FedoraprojectGoogle+3 more
8Backports Sle
ChromeDebian Linux+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extensi...Show more
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.Show less