VYPR

Leap

by OpenSUSE

Source repositories

CVEs (1,917)

  • CVE-2020-10029MedMar 4, 2020
    risk 0.36cvss 5.5epss 0.01

    The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is…

  • CVE-2020-7063MedFeb 27, 2020
    risk 0.36cvss 5.5epss 0.02

    In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more…

  • CVE-2020-8992MedFeb 14, 2020
    risk 0.36cvss 5.5epss 0.00

    ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.

  • CVE-2020-0549MedJan 28, 2020
    risk 0.36cvss 5.5epss 0.01

    Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-5202MedJan 21, 2020
    risk 0.36cvss 5.5epss 0.00

    apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit…

  • CVE-2019-19727MedJan 13, 2020
    risk 0.36cvss 5.5epss 0.00

    SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.

  • CVE-2019-20053MedDec 27, 2019
    risk 0.36cvss 5.5epss 0.01

    An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.

  • CVE-2019-1551MedDec 6, 2019
    risk 0.36cvss 5.3epss 0.14

    There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult…

  • CVE-2019-19462MedNov 30, 2019
    risk 0.36cvss 5.5epss 0.00

    relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.

  • CVE-2019-19451MedNov 29, 2019
    risk 0.36cvss 5.5epss 0.00

    When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to…

  • CVE-2019-15902MedSep 4, 2019
    risk 0.36cvss 5.6epss 0.01

    A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()"…

  • CVE-2019-15145MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in…

  • CVE-2019-15144MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.

  • CVE-2019-15143MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.

  • CVE-2019-15142MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.

  • CVE-2019-5460MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.03

    Double Free in VLC versions <= 3.0.6 leads to a crash.

  • CVE-2019-14444MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.01

    apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.

  • CVE-2019-14275MedJul 26, 2019
    risk 0.36cvss 5.5epss 0.01

    Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.

  • CVE-2019-14274MedJul 26, 2019
    risk 0.36cvss 5.5epss 0.02

    MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.

  • CVE-2019-14250MedJul 24, 2019
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

Page 61 of 96