cbcvebase.

Opensuse Backports Sle vulnerabilities

325 known vulnerabilities affecting opensuse/backports_sle.

Total CVEs
325
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH168MEDIUM129LOW1

Vulnerabilities

Page 10 of 17
CVE-2019-13602P3HIGHCVSS 7.8v15.02019-07-14
CVE-2019-13602 [HIGH] CWE-191 CVE-2019-13602: An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
nvd
CVE-2019-19917P3HIGHCVSS 7.8v15.02019-12-20
CVE-2019-19917 [HIGH] CWE-120 CVE-2019-19917: Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
nvd
CVE-2020-10593P3HIGHCVSS 7.5v15.02020-03-23
CVE-2020-10593 [HIGH] CWE-401 CVE-2020-10593: Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit.
nvd
CVE-2020-16118P3HIGHCVSS 7.5v15.02020-07-29
CVE-2020-16118 [HIGH] CWE-476 CVE-2020-16118: In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL poi In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.
nvd
CVE-2019-9896P3HIGHCVSS 7.8v15.02019-03-21
CVE-2019-9896 [HIGH] CWE-427 CVE-2019-9896: In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
nvd
CVE-2020-15980P3HIGHCVSS 7.8v15.02020-11-03
CVE-2020-15980 [HIGH] CVE-2020-15980: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents.
nvd
CVE-2019-11779P3MEDIUMCVSS 6.5v15.02019-09-19
CVE-2019-11779 [MEDIUM] CWE-754 CVE-2019-11779: In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet c In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
nvd
CVE-2019-9494P3MEDIUMCVSS 5.9v15.02019-04-17
CVE-2019-9494 [MEDIUM] CWE-208 CVE-2019-9494: The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE supp
nvd
CVE-2019-11007P3HIGHCVSS 8.1v15.02019-04-08
CVE-2019-11007 [HIGH] CWE-125 CVE-2019-11007: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGIma In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
nvd
CVE-2019-9771P3HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9771 [HIGH] CWE-476 CVE-2019-9771: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.
nvd
CVE-2019-9776P4HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9776 [HIGH] CWE-476 CVE-2019-9776: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779).
nvd
CVE-2019-9772P3HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9772 [HIGH] CWE-476 CVE-2019-9772: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.
nvd
CVE-2019-13706P4HIGHCVSS 7.8v15.02019-11-25
CVE-2019-13706 [HIGH] CWE-787 CVE-2019-13706: Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attack Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-13702P4HIGHCVSS 7.8v15.02019-11-25
CVE-2019-13702 [HIGH] CWE-269 CVE-2019-13702: Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.
nvd
CVE-2016-10937P4HIGHCVSS 7.5v15.02019-09-08
CVE-2016-10937 [HIGH] CWE-295 CVE-2016-10937: IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
nvd
CVE-2019-14856P4MEDIUMCVSS 6.5v15.02019-11-26
CVE-2019-14856 [MEDIUM] CWE-287 CVE-2019-14856: ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
nvd
CVE-2019-20011P4HIGHCVSS 8.8v15.02019-12-27
CVE-2019-20011 [HIGH] CWE-125 CVE-2019-20011: An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
nvd
CVE-2020-15983P4HIGHCVSS 7.8v15.02020-11-03
CVE-2020-15983 [HIGH] CWE-20 CVE-2020-15983: Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a l Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-12050P4HIGHCVSS 7.0v15.02020-04-30
CVE-2020-12050 [HIGH] CWE-362 CVE-2020-12050: SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition lea SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
nvd
CVE-2019-9777P4HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9777 [HIGH] CWE-125 CVE-2019-9777: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec.
nvd
Opensuse Backports Sle vulnerabilities | cvebase