Opensuse Backports vulnerabilities
96 known vulnerabilities affecting opensuse/backports.
Total CVEs
96
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH39MEDIUM49
Vulnerabilities
Page 4 of 5
CVE-2019-5459P4HIGHCVSS 7.1vsle-152019-07-30
CVE-2019-5459 [HIGH] CWE-191 CVE-2019-5459: An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
nvd
CVE-2019-5805P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5805 [MEDIUM] CWE-416 CVE-2019-5805: Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potent
Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-13713P4MEDIUMCVSS 6.5vsle-152019-11-25
CVE-2019-13713 [MEDIUM] CVE-2019-13713: Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remot
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6495P4MEDIUMCVSS 6.5vsle-152020-06-03
CVE-2020-6495 [MEDIUM] CWE-276 CVE-2020-6495: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2019-5793P4MEDIUMCVSS 6.5vsle-152019-05-23
CVE-2019-5793 [MEDIUM] CWE-20 CVE-2019-5793: Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remot
Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page.
nvd
CVE-2019-5814P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5814 [MEDIUM] CWE-352 CVE-2019-5814: Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5810P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5810 [MEDIUM] CWE-312 CVE-2019-5810: Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to ob
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-5801P4MEDIUMCVSS 6.5vsle-152019-05-23
CVE-2019-5801 [MEDIUM] CWE-20 CVE-2019-5801: Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote
Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-5834P4MEDIUMCVSS 6.5vsle-152019-06-27
CVE-2019-5834 [MEDIUM] CWE-346 CVE-2019-5834: Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attack
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2020-6610P4MEDIUMCVSS 6.5vsle-152020-01-08
CVE-2020-6610 [MEDIUM] CWE-770 CVE-2020-6610: GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
nvd
CVE-2020-6425P4MEDIUMCVSS 5.4vsle-152020-03-23
CVE-2020-6425 [MEDIUM] CWE-20 CVE-2020-6425: Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an att
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
nvd
CVE-2019-13711P4MEDIUMCVSS 5.3vsle-152019-11-25
CVE-2019-13711 [MEDIUM] CVE-2019-13711: Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remot
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-15624P4MEDIUMCVSS 4.9vsle-152020-02-04
CVE-2019-15624 [MEDIUM] CWE-20 CVE-2019-15624: Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
nvd
CVE-2020-5202P4MEDIUMCVSS 5.5vsle-152020-01-21
CVE-2020-5202 [MEDIUM] CVE-2020-5202: apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardco
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-n
nvd
CVE-2019-16709P4MEDIUMCVSS 6.5vsle-152019-09-23
CVE-2019-16709 [MEDIUM] CWE-401 CVE-2019-16709: ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
nvd
CVE-2019-5823P4MEDIUMCVSS 5.4vsle-152019-06-27
CVE-2019-5823 [MEDIUM] CWE-601 CVE-2019-5823: Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-18899P4MEDIUMCVSS 5.5vsle-152020-01-23
CVE-2019-18899 [MEDIUM] CWE-269 CVE-2019-18899: The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cac
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.
nvd
CVE-2020-6441P4MEDIUMCVSS 4.3vsle-152020-04-13
CVE-2020-6441 [MEDIUM] CWE-276 CVE-2020-6441: Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote a
Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
nvd
CVE-2019-5460P4MEDIUMCVSS 5.5vsle-152019-07-30
CVE-2019-5460 [MEDIUM] CWE-415 CVE-2019-5460: Double Free in VLC versions <= 3.0.6 leads to a crash.
Double Free in VLC versions <= 3.0.6 leads to a crash.
nvd
CVE-2020-6437P4MEDIUMCVSS 4.3vsle-152020-04-13
CVE-2020-6437 [MEDIUM] CVE-2020-6437: Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote atta
Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
nvd