Opensuse Backports Sle vulnerabilities
325 known vulnerabilities affecting opensuse/backports_sle.
Total CVEs
325
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH168MEDIUM129LOW1
Vulnerabilities
Page 9 of 17
CVE-2019-12098P3HIGHCVSS 7.4v15.02019-05-15
CVE-2019-12098 [HIGH] CWE-295 CVE-2019-12098: In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exch
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
nvd
CVE-2019-14846P3HIGHCVSS 7.8v15.02019-10-08
CVE-2019-14846 [HIGH] CWE-117 CVE-2019-14846: In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-e
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
nvd
CVE-2020-6609P3HIGHCVSS 8.8v15.02020-01-08
CVE-2020-6609 [HIGH] CWE-125 CVE-2020-6609: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
nvd
CVE-2019-20014P3HIGHCVSS 8.8v15.02019-12-27
CVE-2019-20014 [HIGH] CWE-415 CVE-2019-20014: An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
nvd
CVE-2019-9770P3HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9770 [HIGH] CWE-787 CVE-2019-9770: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in t
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension.
nvd
CVE-2019-9773P3HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9773 [HIGH] CWE-787 CVE-2019-9773: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in t
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.
nvd
CVE-2020-6095P3HIGHCVSS 7.5v15.02020-03-27
CVE-2020-6095 [HIGH] CWE-690 CVE-2020-6095: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2019-19918P3HIGHCVSS 7.8v15.02019-12-20
CVE-2019-19918 [HIGH] CWE-787 CVE-2019-19918: Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
nvd
CVE-2020-9272P3HIGHCVSS 7.5v15.02020-02-20
CVE-2020-9272 [HIGH] CWE-125 CVE-2020-9272: ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_tex
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
nvd
CVE-2020-6574P3HIGHCVSS 7.8v15.02020-09-21
CVE-2020-6574 [HIGH] CVE-2020-6574: Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.
nvd
CVE-2020-16007P3HIGHCVSS 7.8v15.02020-11-03
CVE-2020-16007 [HIGH] CWE-59 CVE-2020-16007: Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local at
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
nvd
CVE-2020-6477P3HIGHCVSS 7.8v15.02020-05-21
CVE-2020-6477 [HIGH] CWE-59 CVE-2020-6477: Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a l
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.
nvd
CVE-2019-9779P3HIGHCVSS 7.5v15.02019-03-14
CVE-2019-9779 [HIGH] CVE-2019-9779: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776).
nvd
CVE-2020-6510P3HIGHCVSS 7.8v15.02020-07-22
CVE-2020-6510 [HIGH] CWE-787 CVE-2020-6510: Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote att
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-11653P3HIGHCVSS 7.5v15.02020-04-08
CVE-2020-11653 [HIGH] CWE-617 CVE-2020-11653: An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x b
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
nvd
CVE-2020-12108P3MEDIUMCVSS 6.5v15.02020-05-06
CVE-2020-12108 [MEDIUM] CWE-74 CVE-2020-12108: /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
nvd
CVE-2019-14864P3MEDIUMCVSS 6.5v15.02020-01-02
CVE-2019-14864 [MEDIUM] CWE-117 CVE-2019-14864: Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, i
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
nvd
CVE-2020-6614P3HIGHCVSS 8.1v15.02020-01-08
CVE-2020-6614 [HIGH] CWE-125 CVE-2020-6614: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
nvd
CVE-2020-6612P3HIGHCVSS 8.1v15.02020-01-08
CVE-2020-6612 [HIGH] CWE-125 CVE-2020-6612: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
nvd
CVE-2020-6613P3HIGHCVSS 8.1v15.02020-01-08
CVE-2020-6613 [HIGH] CWE-125 CVE-2020-6613: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
nvd