cbcvebase.

Opensuse Backports Sle vulnerabilities

325 known vulnerabilities affecting opensuse/backports_sle.

Total CVEs
325
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH168MEDIUM129LOW1

Vulnerabilities

Page 6 of 17
CVE-2020-15970P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15970 [HIGH] CWE-416 CVE-2020-15970: Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compr Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-15971P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15971 [HIGH] CWE-416 CVE-2020-15971: Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-8955P3CRITICALCVSS 9.8v15.02020-02-12
CVE-2020-8955 [CRITICAL] CWE-120 CVE-2020-8955: irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
nvd
CVE-2020-10802P3HIGHCVSS 8.0v15.02020-03-22
CVE-2020-10802 [HIGH] CWE-89 CVE-2020-10802: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discover In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be perform
nvd
CVE-2020-12244P3HIGHCVSS 7.5v15.02020-05-19
CVE-2020-12244 [HIGH] CWE-347 CVE-2020-12244: An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
nvd
CVE-2020-6471P3CRITICALCVSS 9.6v15.02020-05-21
CVE-2020-6471 [CRITICAL] CWE-276 CVE-2020-6471: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2020-25829P3HIGHCVSS 7.5v15.02020-10-16
CVE-2020-25829 [HIGH] CVE-2020-25829: An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3 An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (
nvd
CVE-2019-11505P3HIGHCVSS 8.8v15.02019-04-24
CVE-2019-11505 [HIGH] CWE-787 CVE-2019-11505: In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overf In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.
nvd
CVE-2019-12921P3MEDIUMCVSS 6.5v15.02020-03-18
CVE-2019-12921 [MEDIUM] CWE-77 CVE-2019-12921: In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitra In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
nvd
CVE-2020-6413P3HIGHCVSS 8.8v15.02020-02-11
CVE-2020-6413 [HIGH] CVE-2020-6413: Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attack Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page.
nvd
CVE-2020-15978P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15978 [HIGH] CWE-20 CVE-2020-15978: Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-15976P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15976 [HIGH] CWE-416 CVE-2020-15976: Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6496P3HIGHCVSS 8.8v15.02020-06-03
CVE-2020-6496 [HIGH] CWE-416 CVE-2020-6496: Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-16008P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-16008 [HIGH] CWE-787 CVE-2020-16008: Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
nvd
CVE-2020-7040P3HIGHCVSS 8.1v15.02020-01-21
CVE-2020-7040 [HIGH] CWE-59 CVE-2020-7040: storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
nvd
CVE-2020-8164P3HIGHCVSS 7.5v15.02020-06-19
CVE-2020-8164 [HIGH] CWE-502 CVE-2020-8164: A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which c A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
nvd
CVE-2020-10804P3HIGHCVSS 8.0v15.02020-03-22
CVE-2020-10804 [HIGH] CWE-89 CVE-2020-10804: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retr In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with
nvd
CVE-2020-14352P3HIGHCVSS 8.0v15.02020-08-30
CVE-2020-14352 [HIGH] CWE-22 CVE-2020-14352: A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in
nvd
CVE-2019-5164P3HIGHCVSS 7.8v15.02019-12-03
CVE-2019-5164 [HIGH] CWE-306 CVE-2019-5164: An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3 An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
nvd
CVE-2019-9775P3CRITICALCVSS 9.1v15.02019-03-14
CVE-2019-9775 [CRITICAL] CWE-125 CVE-2019-9775: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the func An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec.
nvd
Opensuse Backports Sle vulnerabilities | cvebase