VYPR

Leap

by OpenSUSE

Source repositories

CVEs (1,917)

  • CVE-2020-15229HigOct 14, 2020
    risk 0.46cvss 8.2epss 0.02

    Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the…

  • CVE-2020-14377HigSep 30, 2020
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can…

  • CVE-2020-25599HigSep 23, 2020
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to…

  • CVE-2020-14393HigSep 16, 2020
    risk 0.46cvss 7.1epss 0.01

    A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.

  • CVE-2020-14349HigAug 24, 2020
    risk 0.46cvss 7.1epss 0.02

    It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in…

  • CVE-2020-6519MedJul 22, 2020
    risk 0.46cvss 6.5epss 0.11

    Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2020-1967HigApr 21, 2020
    risk 0.46cvss 7.5epss 0.53

    Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or…

  • CVE-2020-2914HigApr 15, 2020
    risk 0.46cvss 7.0epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2020-2913HigApr 15, 2020
    risk 0.46cvss 7.0epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2020-0556HigMar 12, 2020
    risk 0.46cvss 7.1epss 0.01

    Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access

  • CVE-2020-8648HigFeb 6, 2020
    risk 0.46cvss 7.1epss 0.01

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

  • CVE-2019-18932HigJan 21, 2020
    risk 0.46cvss 7.0epss 0.00

    log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create…

  • CVE-2019-17358HigDec 12, 2019
    risk 0.46cvss 8.1epss 0.03

    Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory…

  • CVE-2019-18683HigNov 4, 2019
    risk 0.46cvss 7.0epss 0.01

    An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race…

  • CVE-2019-17498HigOct 21, 2019
    risk 0.46cvss 8.1epss 0.04

    In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive…

  • CVE-2019-9458HigSep 6, 2019
    risk 0.46cvss 7.0epss 0.00

    In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-5459HigJul 30, 2019
    risk 0.46cvss 7.1epss 0.03

    An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.

  • CVE-2019-7443HigMay 7, 2019
    risk 0.46cvss 8.1epss 0.02

    KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth…

  • CVE-2018-20506HigApr 3, 2019
    risk 0.46cvss 8.1epss 0.08

    SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by…

  • CVE-2018-20346HigDec 21, 2018
    risk 0.46cvss 8.1epss 0.12

    SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run…

Page 40 of 96