opensuse project kayıtları
opensuse project üreticisine ait 54 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %79,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer13
- CWE-20 Improper Input Validation8
- CWE-399 Resource Management Errors4
- CWE-125 Out-of-bounds Read3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
54 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2017-6542Kavram kanıtı | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an aputty · putty · CWE-119 | Kritik9,8 | — | %21,8 | 27 Mar 2017 |
42Planlayın | CVE-2014-1528İstismar yok | The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote amozilla · firefox · CWE-119 | Kritik10,0 | — | %5,6 | 30 Nis 2014 |
40Planlayın | CVE-2014-9846İstismar yok | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.imagemagick · imagemagick · CWE-119 | Kritik9,8 | — | %4,9 | 20 Mar 2017 |
40Planlayın | CVE-2014-9847İstismar yok | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.imagemagick · imagemagick · CWE-119 | Kritik9,8 | — | %4,6 | 20 Mar 2017 |
40Planlayın | CVE-2016-9961İstismar yok | game-music-emu before 0.6.1 mishandles unspecified integer values.game-music-emu project · game-music-emu · CWE-189 | Kritik9,8 | — | %4,4 | 6 Haz 2017 |
40Planlayın | CVE-2014-9841İstismar yok | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, reimagemagick · imagemagick · CWE-388 | Kritik9,8 | — | %3,9 | 20 Mar 2017 |
40Planlayın | CVE-2014-9843İstismar yok | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.imagemagick · imagemagick · CWE-119 | Kritik9,8 | — | %3,9 | 20 Mar 2017 |
39İzleyin | CVE-2014-1494İstismar yok | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers tmozilla · seamonkey | Kritik9,3 | — | %5,1 | 19 Mar 2014 |
32İzleyin | CVE-2016-10048İstismar yok | Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecifieimagemagick · imagemagick · CWE-22 | Yüksek7,5 | — | %6,5 | 23 Mar 2017 |
32İzleyin | CVE-2015-3405İstismar yok | ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machinntp · ntp · CWE-331 | Yüksek7,5 | — | %5,3 | 9 Ağu 2017 |
32İzleyin | CVE-2016-9958İstismar yok | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.opensuse · leap · CWE-119 | Yüksek7,8 | — | %2,3 | 12 Nis 2017 |
32İzleyin | CVE-2016-9959İstismar yok | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.opensuse · leap · CWE-125 | Yüksek7,8 | — | %2,3 | 12 Nis 2017 |
32İzleyin | CVE-2016-9957İstismar yok | Stack-based buffer overflow in game-music-emu before 0.6.1.opensuse · leap · CWE-119 | Yüksek7,8 | — | %1,9 | 12 Nis 2017 |
31İzleyin | CVE-2014-9848İstismar yok | Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).imagemagick · imagemagick · CWE-399 | Yüksek7,5 | — | %3,7 | 20 Mar 2017 |
31İzleyin | CVE-2014-9851İstismar yok | ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).imagemagick · imagemagick · CWE-20 | Yüksek7,5 | — | %3,7 | 20 Mar 2017 |
31İzleyin | CVE-2014-9850İstismar yok | Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).imagemagick · imagemagick · CWE-399 | Yüksek7,5 | — | %3,6 | 20 Mar 2017 |
31İzleyin | CVE-2014-9849İstismar yok | The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).imagemagick · imagemagick · CWE-400 | Yüksek7,5 | — | %3,6 | 20 Mar 2017 |
31İzleyin | CVE-2014-9842İstismar yok | Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memorimagemagick · imagemagick · CWE-400 | Yüksek7,5 | — | %3,6 | 20 Mar 2017 |
31İzleyin | CVE-2016-7797İstismar yok | Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an clusterlabs · pacemaker · CWE-254 | Yüksek7,5 | — | %3,3 | 24 Mar 2017 |
31İzleyin | CVE-2016-1254İstismar yok | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.torproject · tor · CWE-119 | Yüksek7,5 | — | %3,0 | 5 Ara 2017 |
31İzleyin | CVE-2015-3138İstismar yok | print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).tcpdump · tcpdump · CWE-20 | Yüksek7,5 | — | %2,3 | 27 Eyl 2017 |
31İzleyin | CVE-2017-17806İstismar yok | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithmlinux · linux kernel · CWE-787 | Yüksek7,8 | — | %0,6 | 20 Ara 2017 |
31İzleyin | CVE-2017-17805İstismar yok | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker alinux · linux kernel · CWE-20 | Yüksek7,8 | — | %0,4 | 20 Ara 2017 |
29İzleyin | CVE-2014-1542İstismar yok | Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrarmozilla · firefox · CWE-119 | Orta6,8 | — | %5,3 | 11 Haz 2014 |
27İzleyin | CVE-2014-4258İstismar yok | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticateoracle · mysql | Orta6,5 | — | %3,5 | 17 Tem 2014 |
- CVE-2017-654246Planlayın
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a
KritikCVSS 9,8Kavram kanıtıEPSS %22putty · putty27 Mar 2017
- CVE-2014-152842Planlayın
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote a
KritikCVSS 10,0İstismar yokEPSS %6mozilla · firefox30 Nis 2014
- CVE-2014-984640Planlayın
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick20 Mar 2017
- CVE-2014-984740Planlayın
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
KritikCVSS 9,8İstismar yokEPSS %5imagemagick · imagemagick20 Mar 2017
- CVE-2016-996140Planlayın
game-music-emu before 0.6.1 mishandles unspecified integer values.
KritikCVSS 9,8İstismar yokEPSS %4game-music-emu project · game-music-emu6 Haz 2017
- CVE-2014-984140Planlayın
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, re
KritikCVSS 9,8İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2014-984340Planlayın
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
KritikCVSS 9,8İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2014-149439İzleyin
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers t
KritikCVSS 9,3İstismar yokEPSS %5mozilla · seamonkey19 Mar 2014
- CVE-2016-1004832İzleyin
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecifie
YüksekCVSS 7,5İstismar yokEPSS %7imagemagick · imagemagick23 Mar 2017
- CVE-2015-340532İzleyin
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machin
YüksekCVSS 7,5İstismar yokEPSS %5ntp · ntp9 Ağu 2017
- CVE-2016-995832İzleyin
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
YüksekCVSS 7,8İstismar yokEPSS %2opensuse · leap12 Nis 2017
- CVE-2016-995932İzleyin
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
YüksekCVSS 7,8İstismar yokEPSS %2opensuse · leap12 Nis 2017
- CVE-2016-995732İzleyin
Stack-based buffer overflow in game-music-emu before 0.6.1.
YüksekCVSS 7,8İstismar yokEPSS %2opensuse · leap12 Nis 2017
- CVE-2014-984831İzleyin
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
YüksekCVSS 7,5İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2014-985131İzleyin
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
YüksekCVSS 7,5İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2014-985031İzleyin
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
YüksekCVSS 7,5İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2014-984931İzleyin
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
YüksekCVSS 7,5İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2014-984231İzleyin
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memor
YüksekCVSS 7,5İstismar yokEPSS %4imagemagick · imagemagick20 Mar 2017
- CVE-2016-779731İzleyin
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an
YüksekCVSS 7,5İstismar yokEPSS %3clusterlabs · pacemaker24 Mar 2017
- CVE-2016-125431İzleyin
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
YüksekCVSS 7,5İstismar yokEPSS %3torproject · tor5 Ara 2017
- CVE-2015-313831İzleyin
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
YüksekCVSS 7,5İstismar yokEPSS %2tcpdump · tcpdump27 Eyl 2017
- CVE-2017-1780631İzleyin
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm
YüksekCVSS 7,8İstismar yokEPSS %1linux · linux kernel20 Ara 2017
- CVE-2017-1780531İzleyin
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker a
YüksekCVSS 7,8İstismar yokEPSS %0linux · linux kernel20 Ara 2017
- CVE-2014-154229İzleyin
Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrar
OrtaCVSS 6,8İstismar yokEPSS %5mozilla · firefox11 Haz 2014
- CVE-2014-425827İzleyin
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticate
OrtaCVSS 6,5İstismar yokEPSS %3oracle · mysql17 Tem 2014