VYPR

Leap

by OpenSUSE

Source repositories

CVEs (1,917)

  • CVE-2019-16709MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.03

    ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.

  • CVE-2019-16708MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.

  • CVE-2019-14806HigAug 9, 2019
    risk 0.42cvss 7.5epss 0.02

    Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

  • CVE-2019-14492HigAug 1, 2019
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

  • CVE-2019-14383MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

  • CVE-2018-20860MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    libopenmpt before 0.3.13 allows a crash with malformed MED files.

  • CVE-2019-2863MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2019-2848MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2019-11725MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing…

  • CVE-2019-11721MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

  • CVE-2019-13626MedJul 17, 2019
    risk 0.42cvss 6.5epss 0.02

    SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

  • CVE-2019-5837MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5835MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2019-5834MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-5832MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5830MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5818MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.

  • CVE-2019-5814MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5810MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-5805MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

Page 50 of 96