Opensuse Backports Sle vulnerabilities
325 known vulnerabilities affecting opensuse/backports_sle.
Total CVEs
325
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH168MEDIUM129LOW1
Vulnerabilities
Page 1 of 17
CVE-2020-12641P1CRITICALCVSS 9.8KEVPoCv15.02020-05-04
CVE-2020-12641 [CRITICAL] CWE-78 CVE-2020-12641: rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via she
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
nvd
CVE-2020-15999P1CRITICALCVSS 9.6KEVPoCv15.02020-11-03
CVE-2020-15999 [CRITICAL] CWE-787 CVE-2020-15999: Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker t
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16009P1HIGHCVSS 8.8KEVv15.02020-11-03
CVE-2020-16009 [HIGH] CWE-787 CVE-2020-16009: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5736P1HIGHCVSS 8.6ExploitedPoCv15.02019-02-11
CVE-2019-5736 [HIGH] CWE-78 CVE-2019-5736: runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overw
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to whi
nvd
CVE-2020-13379P1HIGHCVSS 8.2ExploitedPoCv15.02020-06-03
CVE-2020-13379 [HIGH] CWE-918 CVE-2020-13379: The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This v
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid U
nvd
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCv15.02019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2020-26935P2CRITICALCVSS 9.8PoCv15.02020-10-10
CVE-2020-26935 [CRITICAL] CWE-89 CVE-2020-26935: An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL i
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
nvd
CVE-2018-16873P2HIGHCVSS 8.1v15.02018-12-14
CVE-2018-16873 [HIGH] CWE-20 CVE-2018-16873: In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code exec
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://
nvd
CVE-2020-6404P3HIGHCVSS 8.8PoCv15.02020-02-11
CVE-2020-6404 [HIGH] CWE-787 CVE-2020-6404: Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5796P3HIGHCVSS 7.5PoCv15.02019-05-23
CVE-2019-5796 [HIGH] CWE-362 CVE-2019-5796: Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6519P3MEDIUMCVSS 6.5PoCv15.02020-07-22
CVE-2020-6519 [MEDIUM] CVE-2020-6519: Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass cont
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-11800P2CRITICALCVSS 9.8v15.02020-10-07
CVE-2020-11800 [CRITICAL] CVE-2020-11800: Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary co
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
nvd
CVE-2020-8233P2HIGHCVSS 8.8v15.02020-08-17
CVE-2020-8233 [HIGH] CWE-77 CVE-2020-8233: A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticate
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
nvd
CVE-2020-9273P2HIGHCVSS 8.8v15.02020-02-20
CVE-2020-9273 [HIGH] CWE-416 CVE-2020-9273: In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channe
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
nvd
CVE-2019-13767P3HIGHCVSS 8.8v15.02020-01-10
CVE-2019-13767 [HIGH] CWE-416 CVE-2019-13767: Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-24614P3HIGHCVSS 8.8v15.02020-08-25
CVE-2020-24614 [HIGH] CWE-862 CVE-2020-24614: Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated use
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
nvd
CVE-2020-12640P3CRITICALCVSS 9.8v15.02020-05-04
CVE-2020-12640 [CRITICAL] CWE-22 CVE-2020-12640: Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via director
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
nvd
CVE-2020-24972P3HIGHCVSS 8.8v15.02020-08-29
CVE-2020-24972 [HIGH] CWE-116 CVE-2020-24972: The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to exe
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
nvd
CVE-2019-7164P3CRITICALCVSS 9.8v15.02019-02-20
CVE-2019-7164 [CRITICAL] CWE-89 CVE-2019-7164: SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
nvd
CVE-2019-18622P3CRITICALCVSS 9.8v15.02019-11-22
CVE-2019-18622 [CRITICAL] CWE-89 CVE-2019-18622: An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to tri
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
nvd
1 / 17Next →