« Volver al listado

Opensuse Project

Opensuse Project Leap: vulnerabilidades y CVE

Opensuse Project Leap tiene 35 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE35
Últimos 12 meses0
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2017-17806Alta (7.8)0.56%—20 dic 2017
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash…
CVE-2017-17805Alta (7.8)0.45%—20 dic 2017
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface…
CVE-2016-1254Alta (7.5)3.0%—5 dic 2017
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
CVE-2015-3138Alta (7.5)2.3%—28 sept 2017
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
CVE-2015-5203Media (5.5)1.9%—2 ago 2017
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2015-5221Media (5.5)2.2%—25 jul 2017
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG…
CVE-2016-9961Crítica (9.8)4.4%—6 jun 2017
game-music-emu before 0.6.1 mishandles unspecified integer values.
CVE-2016-9960Media (5.5)0.53%—6 jun 2017
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
CVE-2016-9959Alta (7.8)2.3%—12 abr 2017
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
CVE-2016-9958Alta (7.8)2.3%—12 abr 2017
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
CVE-2016-9957Alta (7.8)1.9%—12 abr 2017
Stack-based buffer overflow in game-music-emu before 0.6.1.
CVE-2017-6542Crítica (9.8)22%—27 mar 2017
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain…
CVE-2015-8010Media (6.1)1.5%—27 mar 2017
Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to…
CVE-2016-7797Alta (7.5)3.3%—24 mar 2017
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
CVE-2016-9556Media (5.5)2.3%—23 mar 2017
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
CVE-2016-10048Alta (7.5)6.5%—23 mar 2017
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
CVE-2014-9851Alta (7.5)3.7%—20 mar 2017
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
CVE-2014-9850Alta (7.5)3.6%—20 mar 2017
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
CVE-2014-9849Alta (7.5)3.6%—20 mar 2017
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
CVE-2014-9848Alta (7.5)3.7%—20 mar 2017
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
CVE-2014-9847Crítica (9.8)4.6%—20 mar 2017
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
CVE-2014-9846Crítica (9.8)4.9%—20 mar 2017
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
CVE-2014-9845Media (5.5)1.9%—20 mar 2017
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
CVE-2014-9844Media (5.5)2.1%—20 mar 2017
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
CVE-2014-9843Crítica (9.8)3.9%—20 mar 2017
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2014-9842Alta (7.5)3.6%—20 mar 2017
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
CVE-2014-9841Crítica (9.8)3.9%—20 mar 2017
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
CVE-2017-5938Media (6.1)1.3%—15 mar 2017
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.
CVE-2016-10069Media (5.5)1.9%—2 mar 2017
coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.
CVE-2016-10068Media (5.5)1.9%—2 mar 2017
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.

Otros productos de Opensuse Project