cbcvebase.

Opensuse Backports Sle vulnerabilities

325 known vulnerabilities affecting opensuse/backports_sle.

Total CVEs
325
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH168MEDIUM129LOW1

Vulnerabilities

Page 7 of 17
CVE-2019-9774P3CRITICALCVSS 9.1v15.02019-03-14
CVE-2019-9774 [CRITICAL] CWE-125 CVE-2019-9774: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the func An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.
nvd
CVE-2020-6469P3CRITICALCVSS 9.6v15.02020-05-21
CVE-2020-6469 [CRITICAL] CWE-276 CVE-2020-6469: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2019-11506P3HIGHCVSS 8.8v15.02019-04-24
CVE-2019-11506 [HIGH] CWE-787 CVE-2019-11506: In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer over In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.
nvd
CVE-2020-6381P3HIGHCVSS 8.8v15.02020-02-11
CVE-2020-6381 [HIGH] CWE-190 CVE-2020-6381: Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowe Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6530P3HIGHCVSS 8.8v15.02020-07-22
CVE-2020-6530 [HIGH] CWE-787 CVE-2020-6530: Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an att Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2020-15974P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15974 [HIGH] CWE-190 CVE-2020-15974: Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2020-6450P3HIGHCVSS 8.8v15.02020-04-13
CVE-2020-6450 [HIGH] CWE-416 CVE-2020-6450: Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to pote Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6451P3HIGHCVSS 8.8v15.02020-04-13
CVE-2020-6451 [HIGH] CWE-416 CVE-2020-6451: Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to pote Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6377P3HIGHCVSS 8.8v15.02020-01-10
CVE-2020-6377 [HIGH] CWE-416 CVE-2020-6377: Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potenti Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15992P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15992 [HIGH] CVE-2020-15992: Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remot Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
nvd
CVE-2020-15975P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15975 [HIGH] CWE-190 CVE-2020-15975: Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13700P3HIGHCVSS 8.8v15.02019-11-25
CVE-2019-13700 [HIGH] CWE-787 CVE-2019-13700: Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remo Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15987P3HIGHCVSS 8.8v15.02020-11-03
CVE-2020-15987 [HIGH] CWE-416 CVE-2020-15987: Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potenti Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC stream.
nvd
CVE-2019-16159P3HIGHCVSS 7.5v15.02019-09-09
CVE-2019-16159 [HIGH] CWE-787 CVE-2019-16159: BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer over BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a sufficient message length causes
nvd
CVE-2020-12066P3HIGHCVSS 7.5v15.02020-04-22
CVE-2020-12066 [HIGH] CWE-20 CVE-2020-12066: CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
nvd
CVE-2020-1772P3HIGHCVSS 7.5v15.02020-03-27
CVE-2020-1772 [HIGH] CWE-155 CVE-2020-1772: It's possible to craft Lost Password requests with wildcards in the Token value, which allows attack It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
nvd
CVE-2019-11008P3HIGHCVSS 8.8v15.02019-04-08
CVE-2019-11008 [HIGH] CWE-787 CVE-2019-11008: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function Wr In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
nvd
CVE-2019-14744P3HIGHCVSS 7.8v15.02019-08-07
CVE-2019-14744 [HIGH] CWE-78 CVE-2019-14744: In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to cod In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
nvd
CVE-2020-6454P3HIGHCVSS 8.8v15.02020-04-13
CVE-2020-6454 [HIGH] CWE-416 CVE-2020-6454: Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convince Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2019-13699P3HIGHCVSS 8.8v15.02019-11-25
CVE-2019-13699 [HIGH] CWE-416 CVE-2019-13699: Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had com Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
Opensuse Backports Sle vulnerabilities | cvebase