VYPR

Leap

by OpenSUSE

Source repositories

CVEs (1,917)

  • CVE-2020-12424MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.01

    When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.

  • CVE-2020-10730MedJul 7, 2020
    risk 0.42cvss 6.5epss 0.02

    A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is…

  • CVE-2020-15563MedJul 7, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A…

  • CVE-2020-10760MedJul 6, 2020
    risk 0.42cvss 6.5epss 0.03

    A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.

  • CVE-2020-12803MedJun 8, 2020
    risk 0.42cvss 6.5epss 0.02

    ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted…

  • CVE-2020-6495MedJun 3, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2020-6494MedJun 3, 2020
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2020-11018MedMay 29, 2020
    risk 0.42cvss 6.5epss 0.02

    In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound reads causing memory allocation with random size. This has been fixed in 2.1.0.

  • CVE-2020-11017MedMay 29, 2020
    risk 0.42cvss 6.5epss 0.02

    In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.

  • CVE-2020-6491MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.

  • CVE-2020-6487MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6486MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6485MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6484MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.

  • CVE-2020-6483MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6482MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2020-6481MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.

  • CVE-2020-6480MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via UI actions.

  • CVE-2020-6479MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.

  • CVE-2020-6478MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.

Page 46 of 96