Opensuse Project
Opensuse Project Leap: vulnerabilidades y CVE
Opensuse Project Leap tiene 35 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-17806 | Alta (7.8) | 0.56% | — | 20 dic 2017 | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash… |
| CVE-2017-17805 | Alta (7.8) | 0.45% | — | 20 dic 2017 | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface… |
| CVE-2016-1254 | Alta (7.5) | 3.0% | — | 5 dic 2017 | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor. |
| CVE-2015-3138 | Alta (7.5) | 2.3% | — | 28 sept 2017 | print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash). |
| CVE-2015-5203 | Media (5.5) | 1.9% | — | 2 ago 2017 | Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file. |
| CVE-2015-5221 | Media (5.5) | 2.2% | — | 25 jul 2017 | Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG… |
| CVE-2016-9961 | Crítica (9.8) | 4.4% | — | 6 jun 2017 | game-music-emu before 0.6.1 mishandles unspecified integer values. |
| CVE-2016-9960 | Media (5.5) | 0.53% | — | 6 jun 2017 | game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). |
| CVE-2016-9959 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. |
| CVE-2016-9958 | Alta (7.8) | 2.3% | — | 12 abr 2017 | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. |
| CVE-2016-9957 | Alta (7.8) | 1.9% | — | 12 abr 2017 | Stack-based buffer overflow in game-music-emu before 0.6.1. |
| CVE-2017-6542 | Crítica (9.8) | 22% | — | 27 mar 2017 | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain… |
| CVE-2015-8010 | Media (6.1) | 1.5% | — | 27 mar 2017 | Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to… |
| CVE-2016-7797 | Alta (7.5) | 3.3% | — | 24 mar 2017 | Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection. |
| CVE-2016-9556 | Media (5.5) | 2.3% | — | 23 mar 2017 | The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. |
| CVE-2016-10048 | Alta (7.5) | 6.5% | — | 23 mar 2017 | Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors. |
| CVE-2014-9851 | Alta (7.5) | 3.7% | — | 20 mar 2017 | ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). |
| CVE-2014-9850 | Alta (7.5) | 3.6% | — | 20 mar 2017 | Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption). |
| CVE-2014-9849 | Alta (7.5) | 3.6% | — | 20 mar 2017 | The png coder in ImageMagick allows remote attackers to cause a denial of service (crash). |
| CVE-2014-9848 | Alta (7.5) | 3.7% | — | 20 mar 2017 | Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption). |
| CVE-2014-9847 | Crítica (9.8) | 4.6% | — | 20 mar 2017 | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact. |
| CVE-2014-9846 | Crítica (9.8) | 4.9% | — | 20 mar 2017 | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. |
| CVE-2014-9845 | Media (5.5) | 1.9% | — | 20 mar 2017 | The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file. |
| CVE-2014-9844 | Media (5.5) | 2.1% | — | 20 mar 2017 | The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file. |
| CVE-2014-9843 | Crítica (9.8) | 3.9% | — | 20 mar 2017 | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. |
| CVE-2014-9842 | Alta (7.5) | 3.6% | — | 20 mar 2017 | Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. |
| CVE-2014-9841 | Crítica (9.8) | 3.9% | — | 20 mar 2017 | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions." |
| CVE-2017-5938 | Media (6.1) | 1.3% | — | 15 mar 2017 | Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name. |
| CVE-2016-10069 | Media (5.5) | 1.9% | — | 2 mar 2017 | coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames. |
| CVE-2016-10068 | Media (5.5) | 1.9% | — | 2 mar 2017 | The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file. |