rpm package
opensuse/neonmodem&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/neonmodem&distro=openSUSE%20Leap%2016.0
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-42506 | Med | 6.1 | < 1.0.7+git0.346d1d3-bp160.1.1 | 1.0.7+git0.346d1d3-bp160.1.1 | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| CVE-2026-42502 | Med | 6.1 | < 1.0.7+git0.346d1d3-bp160.1.1 | 1.0.7+git0.346d1d3-bp160.1.1 | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| CVE-2026-27136 | Med | 6.1 | < 1.0.7+git0.346d1d3-bp160.1.1 | 1.0.7+git0.346d1d3-bp160.1.1 | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| CVE-2026-25681 | Med | 6.1 | < 1.0.7+git0.346d1d3-bp160.1.1 | 1.0.7+git0.346d1d3-bp160.1.1 | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| CVE-2026-25680 | Med | 6.5 | < 1.0.7+git0.346d1d3-bp160.1.1 | 1.0.7+git0.346d1d3-bp160.1.1 | May 22, 2026 | Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. | |
| CVE-2026-33809 | Med | 5.3 | < 1.0.7+git0.346d1d3-bp160.1.1 | 1.0.7+git0.346d1d3-bp160.1.1 | Mar 25, 2026 | A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. |
- affected < 1.0.7+git0.346d1d3-bp160.1.1fixed 1.0.7+git0.346d1d3-bp160.1.1
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- affected < 1.0.7+git0.346d1d3-bp160.1.1fixed 1.0.7+git0.346d1d3-bp160.1.1
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- affected < 1.0.7+git0.346d1d3-bp160.1.1fixed 1.0.7+git0.346d1d3-bp160.1.1
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- affected < 1.0.7+git0.346d1d3-bp160.1.1fixed 1.0.7+git0.346d1d3-bp160.1.1
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- affected < 1.0.7+git0.346d1d3-bp160.1.1fixed 1.0.7+git0.346d1d3-bp160.1.1
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
- affected < 1.0.7+git0.346d1d3-bp160.1.1fixed 1.0.7+git0.346d1d3-bp160.1.1
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.