Opensuse
opensuse
3,271 CVEs • 50 products
Products (50)
Click to collapseToggle
Products (50)
Click to collapse
CVEs (3,271)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Fedoraproject NpmjsOpensuse+2 more6Enterprise Linux Enterprise Linux EusFedora+3 moreNov 21, 2024 Dec 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A prop...Show more |
3Cacti DebianOpensuse3Cacti Debian LinuxLeapNov 21, 2024 Dec 12, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and c...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreNov 21, 2024 Dec 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on th...Show more |
4Debian OpensuseRedhat+1 more4Connect Debian LinuxOpenshift+1 moreNov 21, 2024 Dec 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware |
4Debian FedoraprojectGit Scm+1 more4Debian Linux FedoraGit+1 moreNov 21, 2024 Dec 11, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found i...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 10, 2019 N/A· v4 5.4 MEDIUM· v3 6.4 MEDIUM· v2 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out o...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 10, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba,...Show more |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreNov 21, 2024 Dec 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
8Canonical DebianFedoraproject+5 more15Backports Sle ChromeCommunications Cloud Native Core Network Repository Function+12 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more9Backports ChromeDebian Linux+6 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
7Canonical DebianFedoraproject+4 more9Debian Linux Enterprise Manager Ops CenterFedora+6 moreNov 21, 2024 Dec 6, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and...Show more |
The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control...Show more |
4Debian OpensuseOracle+1 more5Debian Linux LeapSolaris+2 moreNov 21, 2024 Dec 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInf...Show more |
3Aquamaniac DebianOpensuse3Debian Linux GwenhywfarLeapNov 21, 2024 Dec 3, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. |
2Opensuse Shadowsocks3Backports Sle LeapShadowsocks LibevNov 21, 2024 Dec 3, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code executi...Show more |
2Opensuse Shadowsocks3Backports LeapShadowsocks LibevNov 21, 2024 Dec 3, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path...Show more |
2Apache Opensuse3Leap Mod FcgidOpensuseNov 21, 2024 Dec 3, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. |
3Freeradius OpensuseRedhat3Enterprise Linux FreeradiusLeapNov 21, 2024 Dec 3, 2019 N/A· v4 6.5 MEDIUM· v3 2.9 LOW· v2 In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an atta...Show more |