VYPR

Leap

by OpenSUSE

Source repositories

CVEs (1,917)

  • CVE-2020-17367HigAug 11, 2020
    risk 0.51cvss 7.8epss 0.01

    Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.

  • CVE-2020-6510HigJul 22, 2020
    risk 0.51cvss 7.8epss 0.02

    Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-15567HigJul 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of…

  • CVE-2020-15396HigJun 30, 2020
    risk 0.51cvss 7.8epss 0.00

    In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

  • CVE-2020-1269HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264,…

  • CVE-2020-6477HigMay 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.

  • CVE-2020-11866HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.

  • CVE-2020-11865HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.

  • CVE-2020-2929HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the…

  • CVE-2020-11739HigApr 14, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a…

  • CVE-2020-10648HigMar 19, 2020
    risk 0.51cvss 7.8epss 0.01

    Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.

  • CVE-2020-0561HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-17009HigJan 8, 2020
    risk 0.51cvss 7.8epss 0.00

    When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects…

  • CVE-2019-19918HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

  • CVE-2019-19917HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

  • CVE-2019-19604HigDec 11, 2019
    risk 0.51cvss 7.8epss 0.04

    Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.

  • CVE-2019-5164HigDec 3, 2019
    risk 0.51cvss 7.8epss 0.01

    An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network…

  • CVE-2017-5333HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.02

    Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.

  • CVE-2017-5332HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.02

    The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

  • CVE-2017-5331HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.00

    Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

Page 26 of 96