Записи openSUSE
3 295 опубликованных записей вендора opensuse.
Профиль для исследователя
- Попали в KEV
- 59 · 1,8 %
- С эксплойтом
- 85 · 2,6 %
- Pre-auth RCE
- 417
- С записью об исправлении
- 89,5 %
- Медиана: публикация → KEV
- 2577 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer307
- CWE-125 Out-of-bounds Read218
- CWE-416 Use After Free201
- CWE-787 Out-of-bounds Write191
- CWE-20 Improper Input Validation183
- CWE-190 Integer Overflow or Wraparound99
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
3 295 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2014-0497Готовый эксплойт | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Критическая9,8 | KEV | 99,9 % | 5 февр. 2014 г. |
99Срочно | CVE-2020-16846Готовый эксплойт | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Критическая9,8 | KEV | 99,6 % | 6 нояб. 2020 г. |
99Срочно | CVE-2015-5119Готовый эксплойт | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Критическая9,8 | KEV | 99,3 % | 8 июл. 2015 г. |
99Срочно | CVE-2020-1938Готовый эксплойт | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Критическая9,8 | KEV | 99,3 % | 24 февр. 2020 г. |
98Срочно | CVE-2013-0422Готовый эксплойт | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Критическая9,8 | KEV | 97,0 % | 10 янв. 2013 г. |
98Срочно | CVE-2020-11651Готовый эксплойт | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Критическая9,8 | KEV | 96,6 % | 30 апр. 2020 г. |
98Срочно | CVE-2010-0840Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and oracle · jre | Критическая9,8 | KEV | 96,3 % | 1 апр. 2010 г. |
98Срочно | CVE-2015-0313Готовый эксплойт | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Критическая9,8 | KEV | 95,3 % | 2 февр. 2015 г. |
97Срочно | CVE-2016-4117Готовый эксплойт | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Критическая9,8 | KEV | 94,4 % | 10 мая 2016 г. |
97Срочно | CVE-2015-5122Готовый эксплойт | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Критическая9,8 | KEV | 94,0 % | 14 июл. 2015 г. |
97Срочно | CVE-2016-3427Готовый эксплойт | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Критическая9,8 | KEV | 92,3 % | 21 апр. 2016 г. |
95Срочно | CVE-2011-0611Готовый эксплойт | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | Высокая8,8 | KEV | 99,4 % | 13 апр. 2011 г. |
94Срочно | CVE-2020-12641Готовый эксплойт | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setroundcube · webmail · CWE-78 | Критическая9,8 | KEV | 84,3 % | 4 мая 2020 г. |
92Срочно | CVE-2016-3714Готовый эксплойт | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | Высокая8,4 | KEV | 97,5 % | 5 мая 2016 г. |
91Срочно | CVE-2015-3043Готовый эксплойт | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attadobe · flash player · CWE-787 | Критическая9,8 | KEV | 73,9 % | 14 апр. 2015 г. |
91Срочно | CVE-2010-4344Готовый эксплойт | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Критическая9,8 | KEV | 71,7 % | 14 дек. 2010 г. |
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
90Срочно | CVE-2019-5418Готовый эксплойт | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted acceprubyonrails · rails · CWE-22 | Высокая7,5 | KEV | 98,5 % | 27 мар. 2019 г. |
90Срочно | CVE-2009-3953Готовый эксплойт | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | Высокая8,8 | KEV | 83,2 % | 13 янв. 2010 г. |
89Срочно | CVE-2016-0752Готовый эксплойт | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, anrubyonrails · rails · CWE-22 | Высокая7,5 | KEV | 95,5 % | 15 февр. 2016 г. |
87Срочно | CVE-2013-0640Готовый эксплойт | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | Высокая7,8 | KEV | 86,9 % | 13 февр. 2013 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-049799Срочно
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player5 февр. 2014 г.
- CVE-2020-1684699Срочно
An issue was discovered in SaltStack Salt through 3002.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %saltstack · salt6 нояб. 2020 г.
- CVE-2015-511999Срочно
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · flash player8 июл. 2015 г.
- CVE-2020-193899Срочно
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · geode24 февр. 2020 г.
- CVE-2013-042298Срочно
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk10 янв. 2013 г.
- CVE-2020-1165198Срочно
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %saltstack · salt30 апр. 2020 г.
- CVE-2010-084098Срочно
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %oracle · jre1 апр. 2010 г.
- CVE-2015-031398Срочно
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %adobe · flash player2 февр. 2015 г.
- CVE-2016-411797Срочно
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player10 мая 2016 г.
- CVE-2015-512297Срочно
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player14 июл. 2015 г.
- CVE-2016-342797Срочно
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %oracle · jdk21 апр. 2016 г.
- CVE-2011-061195Срочно
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %adobe · flash player13 апр. 2011 г.
- CVE-2020-1264194Срочно
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %roundcube · webmail4 мая 2020 г.
- CVE-2016-371492Срочно
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 97 %imagemagick · imagemagick5 мая 2016 г.
- CVE-2015-304391Срочно
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 74 %adobe · flash player14 апр. 2015 г.
- CVE-2010-434491Срочно
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 72 %exim · exim14 дек. 2010 г.
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2019-541890Срочно
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accep
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %rubyonrails · rails27 мар. 2019 г.
- CVE-2009-395390Срочно
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %adobe · acrobat13 янв. 2010 г.
- CVE-2016-075289Срочно
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, an
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 96 %rubyonrails · rails15 февр. 2016 г.
- CVE-2013-064087Срочно
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 87 %adobe · acrobat13 февр. 2013 г.