Opensuse Backports vulnerabilities

96 known vulnerabilities affecting opensuse/backports.

Total CVEs
96
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH39MEDIUM49

Vulnerabilities

Page 3 of 5
CVE-2019-13705MEDIUMCVSS 4.3vsle-152019-11-25
CVE-2019-13705 [MEDIUM] CWE-269 CVE-2019-13705: Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
nvd
CVE-2019-13713MEDIUMCVSS 6.5vsle-152019-11-25
CVE-2019-13713 [MEDIUM] CVE-2019-13713: Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remot Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-16709MEDIUMCVSS 6.5vsle-152019-09-23
CVE-2019-16709 [MEDIUM] CWE-401 CVE-2019-16709: ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
nvd
CVE-2019-14524HIGHCVSS 7.8vsle-152019-08-02
CVE-2019-14524 [HIGH] CVE-2019-14524: An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow vi An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
nvd
CVE-2019-5459HIGHCVSS 7.1vsle-152019-07-30
CVE-2019-5459 [HIGH] CWE-191 CVE-2019-5459: An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
nvd
CVE-2019-5460MEDIUMCVSS 5.5vsle-152019-07-30
CVE-2019-5460 [MEDIUM] CWE-415 CVE-2019-5460: Double Free in VLC versions <= 3.0.6 leads to a crash. Double Free in VLC versions <= 3.0.6 leads to a crash.
nvd
CVE-2019-10163MEDIUMCVSS 4.3vsle-152019-07-30
CVE-2019-10163 [MEDIUM] CWE-770 CVE-2019-10163: A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowin A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.
nvd
CVE-2019-5809HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5809 [HIGH] CWE-416 CVE-2019-5809: Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.
nvd
CVE-2019-5824HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5824 [HIGH] CWE-787 CVE-2019-5824: Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker t Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5819HIGHCVSS 7.8vsle-152019-06-27
CVE-2019-5819 [HIGH] CWE-20 CVE-2019-5819: Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allo Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
nvd
CVE-2019-5827HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5827 [HIGH] CWE-190 CVE-2019-5827: Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attac Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5816HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5816 [HIGH] CWE-664 CVE-2019-5816: Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.
nvd
CVE-2019-5817HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5817 [HIGH] CWE-787 CVE-2019-5817: Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote at Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5811HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5811 [HIGH] CVE-2019-5811: Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-5822HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5822 [HIGH] CVE-2019-5822: Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attac Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-5836HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5836 [HIGH] CWE-787 CVE-2019-5836: Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to po Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5831HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5831 [HIGH] CWE-787 CVE-2019-5831: Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to pot Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5828HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5828 [HIGH] CWE-416 CVE-2019-5828: Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote atta Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2019-5813HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5813 [HIGH] CWE-416 CVE-2019-5813: Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentiall Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5821HIGHCVSS 8.8vsle-152019-06-27
CVE-2019-5821 [HIGH] CWE-190 CVE-2019-5821: Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pote Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd