Suse
Suse Package HUB: vulnerabilidades y CVE
Suse Package HUB tiene 39 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses0
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-1646 | Alta (8.8) | 48% | ⚠ Explotación activa | 29 mar 2016 | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-24368 | Alta (7.5) | 3.3% | — | 19 ago 2020 | Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is… |
| CVE-2020-10803 | Media (5.4) | 1.4% | — | 22 mar 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in… |
| CVE-2020-10802 | Alta (8) | 1.8% | — | 22 mar 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in… |
| CVE-2020-10804 | Alta (8) | 2.4% | — | 22 mar 2020 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A… |
| CVE-2020-6416 | Alta (8.8) | 2.0% | — | 11 feb 2020 | Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6415 | Alta (8.8) | 2.0% | — | 11 feb 2020 | Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6408 | Media (6.5) | 1.6% | — | 11 feb 2020 | Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page. |
| CVE-2020-6406 | Alta (8.8) | 1.8% | — | 11 feb 2020 | Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6404 | Alta (8.8) | 2.0% | — | 11 feb 2020 | Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6403 | Media (4.3) | 1.6% | — | 11 feb 2020 | Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |
| CVE-2020-6402 | Alta (8.8) | 2.7% | — | 11 feb 2020 | Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome… |
| CVE-2020-6400 | Media (6.5) | 2.0% | — | 11 feb 2020 | Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
| CVE-2020-6398 | Alta (8.8) | 1.8% | — | 11 feb 2020 | Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. |
| CVE-2020-6397 | Media (6.5) | 1.9% | — | 11 feb 2020 | Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. |
| CVE-2020-6396 | Media (4.3) | 1.7% | — | 11 feb 2020 | Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |
| CVE-2020-6394 | Media (5.4) | 1.7% | — | 11 feb 2020 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
| CVE-2020-6393 | Media (6.5) | 1.9% | — | 11 feb 2020 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
| CVE-2020-6392 | Media (4.3) | 1.5% | — | 11 feb 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome… |
| CVE-2020-6391 | Media (4.3) | 1.3% | — | 11 feb 2020 | Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page. |
| CVE-2020-6390 | Alta (8.8) | 3.1% | — | 11 feb 2020 | Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6385 | Alta (8.8) | 2.3% | — | 11 feb 2020 | Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page. |
| CVE-2020-6382 | Alta (8.8) | 2.3% | — | 11 feb 2020 | Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-6381 | Alta (8.8) | 2.2% | — | 11 feb 2020 | Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2019-15623 | Media (5.3) | 1.9% | — | 4 feb 2020 | Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled. |
| CVE-2020-7106 | Media (6.1) | 2.2% | — | 16 ene 2020 | Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in… |
| CVE-2019-19925 | Alta (7.5) | 6.8% | — | 24 dic 2019 | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. |
| CVE-2019-19923 | Alta (7.5) | 6.8% | — | 24 dic 2019 | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). |
| CVE-2019-19926 | Alta (7.5) | 7.0% | — | 23 dic 2019 | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for… |
| CVE-2019-19880 | Alta (7.5) | 6.9% | — | 18 dic 2019 | exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. |
| CVE-2019-13764 | Alta (8.8) | 6.4% | — | 10 dic 2019 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Otros productos de Suse
Linux Enterprise Server · 474Linux Enterprise Desktop · 461Linux Enterprise Software Development KIT · 296Suse Linux · 210Suse Linux Enterprise Server · 130Linux Enterprise Workstation Extension · 105Linux Enterprise · 97Suse Linux Enterprise Desktop · 81Linux Enterprise Real Time Extension · 58Linux Enterprise Debuginfo · 54Rancher · 46Suse Linux Enterprise Software Development KIT · 35