← Back

Opensuse

opensuse

Vendor: Opensuse • 1,454 CVEs

CVEs (1,454)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianMozilla+2 more
12Debian Linux
Enterprise Linux AusEnterprise Linux Desktop+9 more
Apr 29, 2026
Feb 19, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operatin...Show more
Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operating a proxy server that provides a 407 HTTP status code accompanied by web script, as demonstrated by a phishing attack on an HTTPS site.Show less
5Canonical
DebianMozilla+2 more
12Debian Linux
Enterprise Linux AusEnterprise Linux Desktop+9 more
Apr 29, 2026
Feb 19, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMo...Show more
Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script.Show less
3Canonical
MozillaOpensuse
6Firefox
OpensuseSeamonkey+3 more
Apr 29, 2026
Feb 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent JavaScript workers from reading the browser-profile dir...Show more
Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent JavaScript workers from reading the browser-profile directory name, which has unspecified impact and remote attack vectors.Show less
4Canonical
DebianMozilla+1 more
7Debian Linux
FirefoxOpensuse+4 more
Apr 29, 2026
Feb 19, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey b...Show more
The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.Show less
4Canonical
MozillaOpensuse+1 more
9Enterprise Linux Aus
Enterprise Linux DesktopEnterprise Linux Eus+6 more
Apr 29, 2026
Feb 19, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of...Show more
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image.Show less
3Canonical
MozillaOpensuse
4Firefox
OpensuseSeamonkey+1 more
Apr 29, 2026
Feb 19, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified v...Show more
Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.Show less
4Adobe
OpensuseRedhat+1 more
9Acrobat
Acrobat ReaderEnterprise Linux Desktop+6 more
Apr 21, 2026
Feb 14, 2013
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February...Show more
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.Show less
4Adobe
OpensuseRedhat+1 more
9Acrobat
Acrobat ReaderEnterprise Linux Desktop+6 more
Apr 21, 2026
Feb 14, 2013
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as expl...Show more
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.Show less
7Canonical
DebianFedoraproject+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+9 more
Apr 29, 2026
Feb 13, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (g...Show more
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.Show less
5Canonical
FedoraprojectOpensuse+2 more
11Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+8 more
Apr 29, 2026
Feb 8, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers t...Show more
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.Show less
4Canonical
FedoraprojectInkscape+1 more
4Fedora
InkscapeOpensuse+1 more
Apr 29, 2026
Jan 18, 2013
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
2Opensuse
Oracle
3Opensuse
VirtualizationVm Virtualbox
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
2.4 LOW· v2
Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The previous informatio...Show more
Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The previous information was obtained from the January 2013 Oracle CPU. Oracle has not commented on claims from another vendor that this issue is related to an incorrect comparison in the vga_draw_text function in Devices/Graphics/DevVGA.cpp, which can cause VirtualBox to "draw more lines than necessary."Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
2Google
Opensuse
3Chrome
OpensuseV8
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have uns...Show more
Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.Show less
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Geolocation implementation in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (application crash) via unknown vectors.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving glyphs.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to printing.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to have an unspecified impact by leveraging access to an extension process.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Jan 15, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for termination of an unspecified data structure, which has unknown impact and attack vectors.