VYPR

Backports Sle

by OpenSUSE

Source repositories

CVEs (327)

  • CVE-2020-12672HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.03

    GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

  • CVE-2020-11653HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.

  • CVE-2019-20637HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be…

  • CVE-2020-10593HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same…

  • CVE-2020-9272HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.

  • CVE-2019-16159HigSep 9, 2019
    risk 0.49cvss 7.5epss 0.03

    BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message.…

  • CVE-2016-10937HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

  • CVE-2019-9779HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776).

  • CVE-2019-9778HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.

  • CVE-2019-9777HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec.

  • CVE-2019-9776HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779).

  • CVE-2019-9773HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.

  • CVE-2019-9772HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.

  • CVE-2019-9771HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.

  • CVE-2019-9770HigMar 14, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension.

  • CVE-2020-15229HigOct 14, 2020
    risk 0.46cvss 8.2epss 0.02

    Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the…

  • CVE-2020-6519MedJul 22, 2020
    risk 0.46cvss 6.5epss 0.11

    Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2020-12050HigApr 30, 2020
    risk 0.46cvss 7.0epss 0.00

    SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.

  • CVE-2019-18932HigJan 21, 2020
    risk 0.46cvss 7.0epss 0.00

    log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create…

  • CVE-2019-5459HigJul 30, 2019
    risk 0.46cvss 7.1epss 0.03

    An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.

Page 9 of 17