Opensuse
Opensuse Backports: vulnerabilidades y CVE
Opensuse Backports tiene 97 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE97
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-45082 | Alta (7.8) | 0.50% | — | 19 feb 2022 | An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines… |
| CVE-2021-46142 | Media (5.5) | 1.1% | — | 6 ene 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. |
| CVE-2021-46141 | Media (5.5) | 1.1% | — | 6 ene 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. |
| CVE-2020-15803 | Media (6.1) | 32% | — | 17 jul 2020 | Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget. |
| CVE-2020-14983 | Crítica (9.8) | 2.2% | — | 22 jun 2020 | The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack. |
| CVE-2020-6495 | Media (6.5) | 1.1% | — | 3 jun 2020 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted… |
| CVE-2020-6493 | Crítica (9.6) | 1.7% | — | 3 jun 2020 | Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
| CVE-2020-6456 | Media (6.5) | 1.4% | — | 13 abr 2020 | Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents. |
| CVE-2020-6455 | Alta (8.8) | 2.0% | — | 13 abr 2020 | Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6452 | Alta (8.8) | 1.9% | — | 13 abr 2020 | Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6446 | Media (6.5) | 1.7% | — | 13 abr 2020 | Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
| CVE-2020-6445 | Media (6.5) | 1.9% | — | 13 abr 2020 | Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
| CVE-2020-6443 | Alta (8.8) | 1.8% | — | 13 abr 2020 | Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page. |
| CVE-2020-6442 | Media (4.3) | 2.0% | — | 13 abr 2020 | Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
| CVE-2020-6441 | Media (4.3) | 1.8% | — | 13 abr 2020 | Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. |
| CVE-2020-6440 | Media (4.3) | 1.2% | — | 13 abr 2020 | Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted… |
| CVE-2020-6439 | Alta (8.8) | 1.8% | — | 13 abr 2020 | Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. |
| CVE-2020-6437 | Media (4.3) | 1.8% | — | 13 abr 2020 | Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application. |
| CVE-2020-6435 | Media (4.3) | 1.7% | — | 13 abr 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. |
| CVE-2020-6433 | Media (4.3) | 1.7% | — | 13 abr 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
| CVE-2020-6432 | Media (4.3) | 1.7% | — | 13 abr 2020 | Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
| CVE-2020-6431 | Media (4.3) | 1.6% | — | 13 abr 2020 | Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page. |
| CVE-2020-10938 | Crítica (9.8) | 5.4% | — | 24 mar 2020 | GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c. |
| CVE-2020-6425 | Media (5.4) | 1.2% | — | 23 mar 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. |
| CVE-2020-10592 | Alta (7.5) | 3.2% | — | 23 mar 2020 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002. |
| CVE-2020-0561 | Alta (7.8) | 0.41% | — | 13 feb 2020 | Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |
| CVE-2019-15624 | Media (4.9) | 1.5% | — | 4 feb 2020 | Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. |
| CVE-2019-15613 | Alta (8) | 1.1% | — | 4 feb 2020 | A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes. |
| CVE-2019-18899 | Media (5.5) | 0.26% | — | 23 ene 2020 | The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue… |
| CVE-2020-5202 | Media (5.5) | 0.46% | — | 21 ene 2020 | apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost… |