← Back

Backports

backports

Vendor: Opensuse • 97 CVEs

CVEs (97)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
3Debian
GraphicsmagickOpensuse
4Backports
Debian LinuxGraphicsmagick+1 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.
4Debian
FedoraprojectGoogle+1 more
4Backports
ChromeDebian Linux+1 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
2Opensuse
Torproject
3Backports
LeapTor
Jun 17, 2026
Mar 23, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
2Intel
Opensuse
3Backports
LeapSoftware Guard Extensions Sdk
Jun 17, 2026
Feb 13, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
3Nextcloud
OpensuseSuse
3Backports
Nextcloud ServerSuse Linux Enterprise Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
2Nextcloud
Opensuse
2Backports
Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
2Apt Cacher Ng Project
Opensuse
2Apt Cacher Ng
Backports
Jun 17, 2026
Jan 23, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue aff...Show more
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.Show less
3Apt Cacher Ng Project
DebianOpensuse
4Apt Cacher Ng
BackportsDebian Linux+1 more
Jun 17, 2026
Jan 21, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port...Show more
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data can leak to unprivileged local users that manage to bind to this port before the apt-cacher-ng daemon can.Show less
2Gnu
Opensuse
3Backports
LeapLibredwg
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
2Opensuse
Upx
3Backports
LeapUpx
Jun 17, 2026
Dec 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
3Debian
GraphicsmagickOpensuse
4Backports
Debian LinuxGraphicsmagick+1 more
Jun 17, 2026
Dec 24, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
3Debian
GraphicsmagickOpensuse
4Backports
Debian LinuxGraphicsmagick+1 more
Jun 17, 2026
Dec 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
3Debian
GraphicsmagickOpensuse
4Backports
Debian LinuxGraphicsmagick+1 more
Jun 17, 2026
Dec 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
6Debian
FedoraprojectGoogle+3 more
9Backports
ChromeDebian Linux+6 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Opensuse
Shadowsocks
3Backports
LeapShadowsocks Libev
Jun 17, 2026
Dec 3, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path...Show more
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.Show less
4Fedoraproject
GoogleOpensuse+1 more
6Backports
ChromeEnterprise Linux Desktop+3 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
2Google
Opensuse
2Backports
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
2Google
Opensuse
2Backports
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.