VYPR

Backports Sle

by OpenSUSE

Source repositories

CVEs (327)

  • CVE-2020-6569MedSep 21, 2020
    risk 0.41cvss 6.3epss 0.01

    Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6444MedApr 13, 2020
    risk 0.41cvss 6.3epss 0.01

    Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-12098HigMay 15, 2019
    risk 0.41cvss 7.4epss 0.02

    In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.

  • CVE-2020-26934MedOct 10, 2020
    risk 0.40cvss 6.1epss 0.02

    phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

  • CVE-2019-11556MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    Pagure before 5.6 allows XSS via the templates/blame.html blame view.

  • CVE-2020-6535MedJul 22, 2020
    risk 0.40cvss 6.1epss 0.01

    Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.

  • CVE-2020-6470MedMay 21, 2020
    risk 0.40cvss 6.1epss 0.01

    Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.

  • CVE-2020-12625MedMay 4, 2020
    risk 0.40cvss 6.1epss 0.03

    An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

  • CVE-2020-12137MedApr 24, 2020
    risk 0.40cvss 6.1epss 0.02

    GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform…

  • CVE-2020-7106MedJan 16, 2020
    risk 0.40cvss 6.1epss 0.02

    Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is…

  • CVE-2019-13714MedNov 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.

  • CVE-2020-13614MedMay 26, 2020
    risk 0.39cvss 5.9epss 0.02

    An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.

  • CVE-2019-9494MedApr 17, 2019
    risk 0.39cvss 5.9epss 0.04

    The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full…

  • CVE-2019-3698MedFeb 28, 2020
    risk 0.37cvss 5.7epss 0.01

    UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This…

  • CVE-2020-15989MedNov 3, 2020
    risk 0.36cvss 5.5epss 0.01

    Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

  • CVE-2020-26164MedOct 7, 2020
    risk 0.36cvss 5.5epss 0.01

    In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.

  • CVE-2019-14905MedMar 31, 2020
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename…

  • CVE-2019-14274MedJul 26, 2019
    risk 0.36cvss 5.5epss 0.02

    MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.

  • CVE-2020-8228MedOct 5, 2020
    risk 0.35cvss 5.3epss 0.02

    A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.

  • CVE-2020-10803MedMar 22, 2020
    risk 0.35cvss 5.4epss 0.01

    In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker…

Page 14 of 17