Novell
Novell Suse Package HUB FOR Suse Linux Enterprise: vulnerabilidades y CVE
Novell Suse Package HUB FOR Suse Linux Enterprise tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-13730 | Alta (8.8) | 1.9% | — | 10 dic 2019 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2019-9811 | Alta (8.3) | 2.6% | — | 23 jul 2019 | As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects… |
| CVE-2019-11717 | Media (5.3) | 2.1% | — | 23 jul 2019 | A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects… |
| CVE-2019-11338 | Alta (8.8) | 2.4% | — | 19 abr 2019 | libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have… |
| CVE-2017-8932 | Media (5.9) | 2.2% | — | 6 jul 2017 | A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive… |
| CVE-2016-4303 | Crítica (9.8) | 7.0% | — | 26 sept 2016 | The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON… |
| CVE-2016-1704 | Alta (8.8) | 1.1% | — | 3 jul 2016 | Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
| CVE-2016-2818 | Alta (8.8) | 3.9% | — | 13 jun 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or… |
| CVE-2016-1658 | Media (4.3) | 1.2% | — | 18 abr 2016 | The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive… |
| CVE-2016-1657 | Media (4.3) | 1.2% | — | 18 abr 2016 | The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote… |
| CVE-2016-1957 | Media (4.3) | 2.2% | — | 13 mar 2016 | Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation… |
| CVE-2016-1956 | Media (6.5) | 2.4% | — | 13 mar 2016 | Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader. |
| CVE-2016-1955 | Media (4.3) | 2.0% | — | 13 mar 2016 | Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated… |
| CVE-2016-1954 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP)… |
| CVE-2016-1953 | Alta (8.8) | 3.2% | — | 13 mar 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code… |
| CVE-2016-1952 | Alta (8.8) | 3.0% | — | 13 mar 2016 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or… |
| CVE-2016-1629 | Crítica (9.8) | 2.6% | — | 21 feb 2016 | Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors. |
Otros productos de Novell
Suse Linux Enterprise Server · 91Suse Linux Enterprise Desktop · 83Groupwise · 75Netware · 72Suse Linux Enterprise Software Development KIT · 65Edirectory · 51Zenworks Configuration Management · 35Suse Linux Enterprise Real Time Extension · 33Iprint · 30Suse Linux Enterprise Debuginfo · 24Suse Linux Enterprise Workstation Extension · 24Suse Linux Enterprise Live Patching · 22