İçeriğe atla
Noroxi

opensuse kayıtları

opensuse üreticisine ait 3.295 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
59 · %1,8
Silahlaştırılmış
85 · %2,6
Pre-auth RCE
417
Düzeltme kaydı olan
%89,5
Yayından KEV’e ortanca
2577 gün

Tüm kayıtlar

3.295 kayıt
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php11 May 2012

  • Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · flash player23 Haz 2015

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · flash player5 Şub 2014

  • An issue was discovered in SaltStack Salt through 3002.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    saltstack · salt6 Kas 2020

  • Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    adobe · flash player8 Tem 2015

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · geode24 Şub 2020

  • Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    oracle · jdk10 Oca 2013

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    saltstack · salt30 Nis 2020

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96

    oracle · jre1 Nis 2010

  • Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    adobe · flash player2 Şub 2015

  • Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    adobe · flash player10 May 2016

  • Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    adobe · flash player14 Tem 2015

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    oracle · jdk21 Nis 2016

  • Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99

    adobe · flash player13 Nis 2011

  • rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration set

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84

    roundcube · webmail4 May 2020

  • The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor

    YüksekCVSS 8,4KEVSilahlaştırılmışEPSS %97

    imagemagick · imagemagick5 May 2016

  • Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %74

    adobe · flash player14 Nis 2015

  • Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %72

    exim · exim14 Ara 2010

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    openssl · openssl7 Nis 2014

  • There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accep

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %99

    rubyonrails · rails27 Mar 2019

  • The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %83

    adobe · acrobat13 Oca 2010

  • Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, an

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %96

    rubyonrails · rails15 Şub 2016

  • Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %87

    adobe · acrobat13 Şub 2013