cbcvebase.

Opensuse Backports vulnerabilities

96 known vulnerabilities affecting opensuse/backports.

Total CVEs
96
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH39MEDIUM49

Vulnerabilities

Page 3 of 5
CVE-2019-5163P3HIGHCVSS 7.5vsle-152019-12-03
CVE-2019-5163 [HIGH] CWE-306 CVE-2019-5163: An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-l An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.
nvd
CVE-2019-19953P3CRITICALCVSS 9.1vsle-152019-12-24
CVE-2019-19953 [CRITICAL] CWE-125 CVE-2019-19953: In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function E In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
nvd
CVE-2021-45082P3HIGHCVSS 7.8vsle-152022-02-19
CVE-2021-45082 [HIGH] CWE-77 CVE-2021-45082: An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_inva An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
nvd
CVE-2020-10592P3HIGHCVSS 7.5vsle-152020-03-23
CVE-2020-10592 [HIGH] CVE-2020-10592: Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
nvd
CVE-2019-15613P3HIGHCVSS 8.0vsle-152020-02-04
CVE-2019-15613 [HIGH] CWE-20 CVE-2019-15613: A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file ext A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
nvd
CVE-2019-14524P3HIGHCVSS 7.8vsle-152019-08-02
CVE-2019-14524 [HIGH] CVE-2019-14524: An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow vi An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
nvd
CVE-2020-0561P4HIGHCVSS 7.8vsle-152020-02-13
CVE-2020-0561 [HIGH] CWE-665 CVE-2020-0561: Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-5819P4HIGHCVSS 7.8vsle-152019-06-27
CVE-2019-5819 [HIGH] CWE-20 CVE-2019-5819: Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allo Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
nvd
CVE-2019-5798P4MEDIUMCVSS 6.5vsle-152019-05-23
CVE-2019-5798 [MEDIUM] CWE-125 CVE-2019-5798: Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote atta Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2019-5835P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5835 [MEDIUM] CWE-125 CVE-2019-5835: Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attack Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2020-6445P4MEDIUMCVSS 6.5vsle-152020-04-13
CVE-2020-6445 [MEDIUM] CWE-276 CVE-2020-6445: Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a re Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-6446P4MEDIUMCVSS 6.5vsle-152020-04-13
CVE-2020-6446 [MEDIUM] CWE-276 CVE-2020-6446: Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a re Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2019-5799P4MEDIUMCVSS 6.5vsle-152019-05-23
CVE-2019-5799 [MEDIUM] CWE-20 CVE-2019-5799: Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior t Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-6456P4MEDIUMCVSS 6.5vsle-152020-04-13
CVE-2020-6456 [MEDIUM] CWE-276 CVE-2020-6456: Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allow Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
nvd
CVE-2019-5818P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5818 [MEDIUM] CWE-908 CVE-2019-5818: Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obt Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
nvd
CVE-2019-5837P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5837 [MEDIUM] CVE-2019-5837: Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote a Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5830P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5830 [MEDIUM] CVE-2019-5830: Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote atta Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5832P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5832 [MEDIUM] CVE-2019-5832: Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a r Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5803P4MEDIUMCVSS 6.5vsle-152019-05-23
CVE-2019-5803 [MEDIUM] CWE-20 CVE-2019-5803: Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 al Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2019-5800P4MEDIUMCVSS 6.5vsle-152019-05-23
CVE-2019-5800 [MEDIUM] CWE-20 CVE-2019-5800: Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote att Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
Opensuse Backports vulnerabilities | cvebase