cbcvebase.

Opensuse Backports Sle vulnerabilities

325 known vulnerabilities affecting opensuse/backports_sle.

Total CVEs
325
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH168MEDIUM129LOW1

Vulnerabilities

Page 11 of 17
CVE-2019-9778P4HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9778 [HIGH] CWE-125 CVE-2019-9778: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.
nvd
CVE-2020-6426P4MEDIUMCVSS 6.5v15.02020-03-23
CVE-2020-6426 [MEDIUM] CWE-787 CVE-2020-6426: Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6401P4MEDIUMCVSS 6.5v15.02020-02-11
CVE-2020-6401 [MEDIUM] CWE-20 CVE-2020-6401: Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2019-10206P4MEDIUMCVSS 6.5v15.02019-11-22
CVE-2019-10206 [MEDIUM] CWE-522 CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
nvd
CVE-2020-15988P4MEDIUMCVSS 6.3v15.02020-11-03
CVE-2020-15988 [MEDIUM] CVE-2020-15988: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allow Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files to execute arbitrary code via a crafted HTML page.
nvd
CVE-2020-6400P4MEDIUMCVSS 6.5v15.02020-02-11
CVE-2020-6400 [MEDIUM] CWE-203 CVE-2020-6400: Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacke Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6399P4MEDIUMCVSS 6.5v15.02020-02-11
CVE-2020-6399 [MEDIUM] CWE-20 CVE-2020-6399: Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-3698P4HIGHCVSS 7.0v15.02020-02-28
CVE-2019-3698 [HIGH] CWE-59 CVE-2019-3698: UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linu UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prio
nvd
CVE-2020-6397P4MEDIUMCVSS 6.5v15.02020-02-11
CVE-2020-6397 [MEDIUM] CVE-2020-6397: Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote atta Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6393P4MEDIUMCVSS 6.5v15.02020-02-11
CVE-2020-6393 [MEDIUM] CWE-862 CVE-2020-6393: Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote att Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6511P4MEDIUMCVSS 6.5v15.02020-07-22
CVE-2020-6511 [MEDIUM] CWE-209 CVE-2020-6511: Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6485P4MEDIUMCVSS 6.5v15.02020-05-21
CVE-2020-6485 [MEDIUM] CWE-20 CVE-2020-6485: Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6561P4MEDIUMCVSS 6.5v15.02020-09-21
CVE-2020-6561 [MEDIUM] CVE-2020-6561: Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allow Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-18932P4HIGHCVSS 7.0v15.02020-01-21
CVE-2019-18932 [HIGH] CWE-59 CVE-2019-18932: log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it (after winning a /tmp/sarg/denied.i
nvd
CVE-2020-6484P4MEDIUMCVSS 6.5v15.02020-05-21
CVE-2020-6484 [MEDIUM] CWE-276 CVE-2020-6484: Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
nvd
CVE-2020-10803P4MEDIUMCVSS 5.4v15.02020-03-22
CVE-2020-10803 [MEDIUM] CWE-79 CVE-2020-10803: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered wh In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which w
nvd
CVE-2020-6558P4MEDIUMCVSS 6.5v15.02020-09-21
CVE-2020-6558 [MEDIUM] CWE-79 CVE-2020-6558: Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a re Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6473P4MEDIUMCVSS 6.5v15.02020-05-21
CVE-2020-6473 [MEDIUM] CWE-203 CVE-2020-6473: Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote att Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6526P4MEDIUMCVSS 6.5v15.02020-07-22
CVE-2020-6526 [MEDIUM] CVE-2020-6526: Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remo Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6521P4MEDIUMCVSS 6.5v15.02020-07-22
CVE-2020-6521 [MEDIUM] CVE-2020-6521: Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
Opensuse Backports Sle vulnerabilities | cvebase