openSUSE records
3,295 published records for vendor opensuse.
Researcher profile
- Entered KEV
- 59 · 1.8%
- Weaponized
- 85 · 2.6%
- Pre-auth RCE
- 417
- With a fix record
- 89.5%
- Median publish → KEV
- 2577 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer307
- CWE-125 Out-of-bounds Read218
- CWE-416 Use After Free201
- CWE-787 Out-of-bounds Write191
- CWE-20 Improper Input Validation183
- CWE-190 Integer Overflow or Wraparound99
The weakness classes this vendor ships most often: where to look.
CWEAll records
3,295 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2012-1823Weaponized | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Critical9.8 | KEV | 100.0% | May 11, 2012 |
99Now | CVE-2015-3113Weaponized | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Critical9.8 | KEV | 99.9% | Jun 23, 2015 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2014-0497Weaponized | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Critical9.8 | KEV | 99.9% | Feb 5, 2014 |
99Now | CVE-2020-16846Weaponized | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Critical9.8 | KEV | 99.6% | Nov 6, 2020 |
99Now | CVE-2015-5119Weaponized | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Critical9.8 | KEV | 99.3% | Jul 8, 2015 |
99Now | CVE-2020-1938Weaponized | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Critical9.8 | KEV | 99.3% | Feb 24, 2020 |
98Now | CVE-2013-0422Weaponized | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Critical9.8 | KEV | 97.0% | Jan 10, 2013 |
98Now | CVE-2020-11651Weaponized | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Critical9.8 | KEV | 96.6% | Apr 30, 2020 |
98Now | CVE-2010-0840Weaponized | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and oracle · jre | Critical9.8 | KEV | 96.3% | Apr 1, 2010 |
98Now | CVE-2015-0313Weaponized | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Critical9.8 | KEV | 95.3% | Feb 2, 2015 |
97Now | CVE-2016-4117Weaponized | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Critical9.8 | KEV | 94.4% | May 10, 2016 |
97Now | CVE-2015-5122Weaponized | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Critical9.8 | KEV | 94.0% | Jul 14, 2015 |
97Now | CVE-2016-3427Weaponized | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Critical9.8 | KEV | 92.3% | Apr 21, 2016 |
95Now | CVE-2011-0611Weaponized | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | High8.8 | KEV | 99.4% | Apr 13, 2011 |
94Now | CVE-2020-12641Weaponized | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setroundcube · webmail · CWE-78 | Critical9.8 | KEV | 84.3% | May 4, 2020 |
92Now | CVE-2016-3714Weaponized | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | High8.4 | KEV | 97.5% | May 5, 2016 |
91Now | CVE-2015-3043Weaponized | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attadobe · flash player · CWE-787 | Critical9.8 | KEV | 73.9% | Apr 14, 2015 |
91Now | CVE-2010-4344Weaponized | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Critical9.8 | KEV | 71.7% | Dec 14, 2010 |
90Now | CVE-2014-0160Weaponized | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | High7.5 | KEV | 100.0% | Apr 7, 2014 |
90Now | CVE-2019-5418Weaponized | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted acceprubyonrails · rails · CWE-22 | High7.5 | KEV | 98.5% | Mar 27, 2019 |
90Now | CVE-2009-3953Weaponized | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | High8.8 | KEV | 83.2% | Jan 13, 2010 |
89Now | CVE-2016-0752Weaponized | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, anrubyonrails · rails · CWE-22 | High7.5 | KEV | 95.5% | Feb 15, 2016 |
87Now | CVE-2013-0640Weaponized | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | High7.8 | KEV | 86.9% | Feb 13, 2013 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2012-182399Now
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpMay 11, 2012
- CVE-2015-311399Now
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerJun 23, 2015
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2014-049799Now
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerFeb 5, 2014
- CVE-2020-1684699Now
An issue was discovered in SaltStack Salt through 3002.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%saltstack · saltNov 6, 2020
- CVE-2015-511999Now
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · flash playerJul 8, 2015
- CVE-2020-193899Now
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · geodeFeb 24, 2020
- CVE-2013-042298Now
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkJan 10, 2013
- CVE-2020-1165198Now
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%saltstack · saltApr 30, 2020
- CVE-2010-084098Now
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and
CriticalCVSS 9.8KEVWeaponizedEPSS 96%oracle · jreApr 1, 2010
- CVE-2015-031398Now
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
CriticalCVSS 9.8KEVWeaponizedEPSS 95%adobe · flash playerFeb 2, 2015
- CVE-2016-411797Now
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerMay 10, 2016
- CVE-2015-512297Now
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerJul 14, 2015
- CVE-2016-342797Now
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
CriticalCVSS 9.8KEVWeaponizedEPSS 92%oracle · jdkApr 21, 2016
- CVE-2011-061195Now
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
HighCVSS 8.8KEVWeaponizedEPSS 99%adobe · flash playerApr 13, 2011
- CVE-2020-1264194Now
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set
CriticalCVSS 9.8KEVWeaponizedEPSS 84%roundcube · webmailMay 4, 2020
- CVE-2016-371492Now
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
HighCVSS 8.4KEVWeaponizedEPSS 97%imagemagick · imagemagickMay 5, 2016
- CVE-2015-304391Now
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att
CriticalCVSS 9.8KEVWeaponizedEPSS 74%adobe · flash playerApr 14, 2015
- CVE-2010-434491Now
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
CriticalCVSS 9.8KEVWeaponizedEPSS 72%exim · eximDec 14, 2010
- CVE-2014-016090Now
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
HighCVSS 7.5KEVWeaponizedEPSS 100%openssl · opensslApr 7, 2014
- CVE-2019-541890Now
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accep
HighCVSS 7.5KEVWeaponizedEPSS 99%rubyonrails · railsMar 27, 2019
- CVE-2009-395390Now
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
HighCVSS 8.8KEVWeaponizedEPSS 83%adobe · acrobatJan 13, 2010
- CVE-2016-075289Now
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, an
HighCVSS 7.5KEVWeaponizedEPSS 96%rubyonrails · railsFeb 15, 2016
- CVE-2013-064087Now
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
HighCVSS 7.8KEVWeaponizedEPSS 87%adobe · acrobatFeb 13, 2013