Opensuse
Opensuse Backports SLE: vulnerabilidades y CVE
Opensuse Backports SLE tiene 326 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 27 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE326
Últimos 12 meses0
Críticas27
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-12641 | Crítica (9.8) | 84% | ⚠ Explotación activa | 4 may 2020 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. |
| CVE-2020-15999 | Crítica (9.6) | 44% | ⚠ Explotación activa | 3 nov 2020 | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16009 | Alta (8.8) | 48% | ⚠ Explotación activa | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-6557 | Media (6.5) | 1.5% | — | 3 nov 2020 | Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
| CVE-2020-16011 | Crítica (9.6) | 2.4% | — | 3 nov 2020 | Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
| CVE-2020-16009 | Alta (8.8) | 48% | ⚠ Explotación activa | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16008 | Alta (8.8) | 1.2% | — | 3 nov 2020 | Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet. |
| CVE-2020-16007 | Alta (7.8) | 0.27% | — | 3 nov 2020 | Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem. |
| CVE-2020-16006 | Alta (8.8) | 1.7% | — | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16005 | Alta (8.8) | 1.7% | — | 3 nov 2020 | Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16004 | Alta (8.8) | 1.5% | — | 3 nov 2020 | Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16003 | Alta (8.8) | 1.5% | — | 3 nov 2020 | Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16002 | Alta (8.8) | 1.7% | — | 3 nov 2020 | Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. |
| CVE-2020-16001 | Alta (8.8) | 1.6% | — | 3 nov 2020 | Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16000 | Alta (8.8) | 1.6% | — | 3 nov 2020 | Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-15999 | Crítica (9.6) | 44% | ⚠ Explotación activa | 3 nov 2020 | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-15992 | Alta (8.8) | 1.4% | — | 3 nov 2020 | Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. |
| CVE-2020-15991 | Alta (8.8) | 1.5% | — | 3 nov 2020 | Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
| CVE-2020-15990 | Alta (8.8) | 1.4% | — | 3 nov 2020 | Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
| CVE-2020-15989 | Media (5.5) | 1.1% | — | 3 nov 2020 | Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. |
| CVE-2020-15988 | Media (6.3) | 1.2% | — | 3 nov 2020 | Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files to execute arbitrary code via a crafted HTML page. |
| CVE-2020-15987 | Alta (8.8) | 1.1% | — | 3 nov 2020 | Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC stream. |
| CVE-2020-15986 | Media (6.5) | 1.3% | — | 3 nov 2020 | Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-15985 | Media (6.5) | 1.6% | — | 3 nov 2020 | Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a crafted HTML page. |
| CVE-2020-15984 | Media (6.5) | 1.3% | — | 3 nov 2020 | Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted URL. |
| CVE-2020-15983 | Alta (7.8) | 0.29% | — | 3 nov 2020 | Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page. |
| CVE-2020-15982 | Media (6.5) | 1.4% | — | 3 nov 2020 | Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
| CVE-2020-15981 | Media (6.5) | 1.4% | — | 3 nov 2020 | Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
| CVE-2020-15980 | Alta (7.8) | 0.25% | — | 3 nov 2020 | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents. |
| CVE-2020-15979 | Alta (8.8) | 1.6% | — | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-15978 | Alta (8.8) | 1.5% | — | 3 nov 2020 | Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. |
| CVE-2020-15977 | Media (6.5) | 1.5% | — | 3 nov 2020 | Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page. |
| CVE-2020-15976 | Alta (8.8) | 1.5% | — | 3 nov 2020 | Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.