cbcvebase.

Opensuse Backports Sle vulnerabilities

325 known vulnerabilities affecting opensuse/backports_sle.

Total CVEs
325
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH168MEDIUM129LOW1

Vulnerabilities

Page 14 of 17
CVE-2020-26934P4MEDIUMCVSS 6.1v15.02020-10-10
CVE-2020-26934 [MEDIUM] CWE-79 CVE-2020-26934: phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a cra phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
nvd
CVE-2020-7106P4MEDIUMCVSS 6.1v15.02020-01-16
CVE-2020-7106 [MEDIUM] CWE-79 CVE-2020-7106: Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.ph Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
nvd
CVE-2019-13709P4MEDIUMCVSS 6.5v15.02019-11-25
CVE-2019-13709 [MEDIUM] CWE-290 CVE-2019-13709: Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
nvd
CVE-2020-13614P4MEDIUMCVSS 5.9v15.02020-05-26
CVE-2020-13614 [MEDIUM] CWE-295 CVE-2020-13614: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verifi An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
nvd
CVE-2019-15623P4MEDIUMCVSS 5.3v15.02020-02-04
CVE-2019-15623 [MEDIUM] CWE-359 CVE-2019-15623: Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
nvd
CVE-2019-20013P4MEDIUMCVSS 6.5v15.02019-12-27
CVE-2019-20013 [MEDIUM] CWE-770 CVE-2019-20013: An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessi An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
nvd
CVE-2019-20009P4MEDIUMCVSS 6.5v15.02019-12-27
CVE-2019-20009 [MEDIUM] CWE-770 CVE-2019-20009: An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessi An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
nvd
CVE-2019-20015P4MEDIUMCVSS 6.5v15.02019-12-27
CVE-2019-20015 [MEDIUM] CWE-770 CVE-2019-20015: An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memo An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
nvd
CVE-2019-20012P4MEDIUMCVSS 6.5v15.02019-12-27
CVE-2019-20012 [MEDIUM] CWE-770 CVE-2019-20012: An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memo An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
nvd
CVE-2019-5794P4MEDIUMCVSS 6.5v15.02019-05-23
CVE-2019-5794 [MEDIUM] CVE-2019-5794: Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowe Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-5802P4MEDIUMCVSS 6.5v15.02019-05-23
CVE-2019-5802 [MEDIUM] CVE-2019-5802: Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2020-8228P4MEDIUMCVSS 5.3v15.02020-10-05
CVE-2020-8228 [MEDIUM] CWE-840 CVE-2020-8228: A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
nvd
CVE-2020-6394P4MEDIUMCVSS 5.4v15.02020-02-11
CVE-2020-6394 [MEDIUM] CVE-2020-6394: Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote att Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-7041P4MEDIUMCVSS 5.3v15.02020-02-27
CVE-2020-7041 [MEDIUM] CWE-295 CVE-2020-7041: An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c misha An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
nvd
CVE-2020-1765P4MEDIUMCVSS 5.3v15.02020-01-10
CVE-2020-1765 [MEDIUM] CWE-472 CVE-2020-1765: An improper control of parameters allows the spoofing of the from fields of the following screens: A An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior v
nvd
CVE-2019-14905P4MEDIUMCVSS 5.6v15.02020-03-31
CVE-2019-14905 [MEDIUM] CWE-20 CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x b A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of con
nvd
CVE-2020-6535P4MEDIUMCVSS 6.1v15.02020-07-22
CVE-2020-6535 [MEDIUM] CWE-79 CVE-2020-6535: Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attack Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2020-6412P4MEDIUMCVSS 5.4v15.02020-02-11
CVE-2020-6412 [MEDIUM] CWE-20 CVE-2020-6412: Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2020-7042P4MEDIUMCVSS 5.3v15.02020-02-27
CVE-2020-7042 [MEDIUM] CWE-295 CVE-2020-7042: An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c misha An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
nvd
CVE-2019-9752P4MEDIUMCVSS 5.4v15.02019-03-13
CVE-2019-9752 [MEDIUM] CWE-79 CVE-2019-9752: An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, a An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling in Kernel/Module
nvd
Opensuse Backports Sle vulnerabilities | cvebase