Записи opensuse project
54 опубликованных записей вендора opensuse project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 79,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer13
- CWE-20 Improper Input Validation8
- CWE-399 Resource Management Errors4
- CWE-125 Out-of-bounds Read3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
54 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2017-6542Proof of concept | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an aputty · putty · CWE-119 | Критическая9,8 | — | 21,8 % | 27 мар. 2017 г. |
42В плане | CVE-2014-1528Эксплойта нет | The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote amozilla · firefox · CWE-119 | Критическая10,0 | — | 5,6 % | 30 апр. 2014 г. |
40В плане | CVE-2014-9846Эксплойта нет | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.imagemagick · imagemagick · CWE-119 | Критическая9,8 | — | 4,9 % | 20 мар. 2017 г. |
40В плане | CVE-2014-9847Эксплойта нет | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.imagemagick · imagemagick · CWE-119 | Критическая9,8 | — | 4,6 % | 20 мар. 2017 г. |
40В плане | CVE-2016-9961Эксплойта нет | game-music-emu before 0.6.1 mishandles unspecified integer values.game-music-emu project · game-music-emu · CWE-189 | Критическая9,8 | — | 4,4 % | 6 июн. 2017 г. |
40В плане | CVE-2014-9841Эксплойта нет | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, reimagemagick · imagemagick · CWE-388 | Критическая9,8 | — | 3,9 % | 20 мар. 2017 г. |
40В плане | CVE-2014-9843Эксплойта нет | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.imagemagick · imagemagick · CWE-119 | Критическая9,8 | — | 3,9 % | 20 мар. 2017 г. |
39Наблюдать | CVE-2014-1494Эксплойта нет | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers tmozilla · seamonkey | Критическая9,3 | — | 5,1 % | 19 мар. 2014 г. |
32Наблюдать | CVE-2016-10048Эксплойта нет | Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecifieimagemagick · imagemagick · CWE-22 | Высокая7,5 | — | 6,5 % | 23 мар. 2017 г. |
32Наблюдать | CVE-2015-3405Эксплойта нет | ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machinntp · ntp · CWE-331 | Высокая7,5 | — | 5,3 % | 9 авг. 2017 г. |
32Наблюдать | CVE-2016-9958Эксплойта нет | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.opensuse · leap · CWE-119 | Высокая7,8 | — | 2,3 % | 12 апр. 2017 г. |
32Наблюдать | CVE-2016-9959Эксплойта нет | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.opensuse · leap · CWE-125 | Высокая7,8 | — | 2,3 % | 12 апр. 2017 г. |
32Наблюдать | CVE-2016-9957Эксплойта нет | Stack-based buffer overflow in game-music-emu before 0.6.1.opensuse · leap · CWE-119 | Высокая7,8 | — | 1,9 % | 12 апр. 2017 г. |
31Наблюдать | CVE-2014-9848Эксплойта нет | Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).imagemagick · imagemagick · CWE-399 | Высокая7,5 | — | 3,7 % | 20 мар. 2017 г. |
31Наблюдать | CVE-2014-9851Эксплойта нет | ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).imagemagick · imagemagick · CWE-20 | Высокая7,5 | — | 3,7 % | 20 мар. 2017 г. |
31Наблюдать | CVE-2014-9850Эксплойта нет | Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).imagemagick · imagemagick · CWE-399 | Высокая7,5 | — | 3,6 % | 20 мар. 2017 г. |
31Наблюдать | CVE-2014-9849Эксплойта нет | The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).imagemagick · imagemagick · CWE-400 | Высокая7,5 | — | 3,6 % | 20 мар. 2017 г. |
31Наблюдать | CVE-2014-9842Эксплойта нет | Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memorimagemagick · imagemagick · CWE-400 | Высокая7,5 | — | 3,6 % | 20 мар. 2017 г. |
31Наблюдать | CVE-2016-7797Эксплойта нет | Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an clusterlabs · pacemaker · CWE-254 | Высокая7,5 | — | 3,3 % | 24 мар. 2017 г. |
31Наблюдать | CVE-2016-1254Эксплойта нет | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.torproject · tor · CWE-119 | Высокая7,5 | — | 3,0 % | 5 дек. 2017 г. |
31Наблюдать | CVE-2015-3138Эксплойта нет | print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).tcpdump · tcpdump · CWE-20 | Высокая7,5 | — | 2,3 % | 27 сент. 2017 г. |
31Наблюдать | CVE-2017-17806Эксплойта нет | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithmlinux · linux kernel · CWE-787 | Высокая7,8 | — | 0,6 % | 20 дек. 2017 г. |
31Наблюдать | CVE-2017-17805Эксплойта нет | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker alinux · linux kernel · CWE-20 | Высокая7,8 | — | 0,4 % | 20 дек. 2017 г. |
29Наблюдать | CVE-2014-1542Эксплойта нет | Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrarmozilla · firefox · CWE-119 | Средняя6,8 | — | 5,3 % | 11 июн. 2014 г. |
27Наблюдать | CVE-2014-4258Эксплойта нет | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticateoracle · mysql | Средняя6,5 | — | 3,5 % | 17 июл. 2014 г. |
- CVE-2017-654246В плане
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an a
КритическаяCVSS 9,8Proof of conceptEPSS 22 %putty · putty27 мар. 2017 г.
- CVE-2014-152842В плане
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote a
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %mozilla · firefox30 апр. 2014 г.
- CVE-2014-984640В плане
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2014-984740В плане
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2016-996140В плане
game-music-emu before 0.6.1 mishandles unspecified integer values.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %game-music-emu project · game-music-emu6 июн. 2017 г.
- CVE-2014-984140В плане
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, re
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2014-984340В плане
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2014-149439Наблюдать
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers t
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %mozilla · seamonkey19 мар. 2014 г.
- CVE-2016-1004832Наблюдать
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecifie
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %imagemagick · imagemagick23 мар. 2017 г.
- CVE-2015-340532Наблюдать
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machin
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %ntp · ntp9 авг. 2017 г.
- CVE-2016-995832Наблюдать
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %opensuse · leap12 апр. 2017 г.
- CVE-2016-995932Наблюдать
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %opensuse · leap12 апр. 2017 г.
- CVE-2016-995732Наблюдать
Stack-based buffer overflow in game-music-emu before 0.6.1.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %opensuse · leap12 апр. 2017 г.
- CVE-2014-984831Наблюдать
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2014-985131Наблюдать
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2014-985031Наблюдать
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2014-984931Наблюдать
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2014-984231Наблюдать
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memor
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %imagemagick · imagemagick20 мар. 2017 г.
- CVE-2016-779731Наблюдать
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %clusterlabs · pacemaker24 мар. 2017 г.
- CVE-2016-125431Наблюдать
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %torproject · tor5 дек. 2017 г.
- CVE-2015-313831Наблюдать
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %tcpdump · tcpdump27 сент. 2017 г.
- CVE-2017-1780631Наблюдать
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %linux · linux kernel20 дек. 2017 г.
- CVE-2017-1780531Наблюдать
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker a
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %linux · linux kernel20 дек. 2017 г.
- CVE-2014-154229Наблюдать
Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrar
СредняяCVSS 6,8Эксплойта нетEPSS 5 %mozilla · firefox11 июн. 2014 г.
- CVE-2014-425827Наблюдать
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticate
СредняяCVSS 6,5Эксплойта нетEPSS 3 %oracle · mysql17 июл. 2014 г.