Skip to main content

Vendor/product archive

opensuse / leap CVEs

Beta · best-effort

1,908 CVEs tagged to opensuse / leap192 Critical, 805 High, 795 Medium, 116 Low, 0 Unrated.

CVE-2016-2815

Published Jun 13, 2016

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application cr…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-5118

Published Jun 10, 2016

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filena…

CVSS 9.8 · Critical

CVE-2016-2150

Published Jun 9, 2016

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.

CVSS 7.1 · High

CVE-2016-0749

Published Jun 9, 2016

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecti…

CVSS 9.8 · Critical

CVE-2016-1702

Published Jun 5, 2016

The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attacke…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1699

Published Jun 5, 2016

WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remot…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1698

Published Jun 5, 2016

The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which migh…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1697

Published Jun 5, 2016

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1696

Published Jun 5, 2016

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspec…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1694

Published Jun 5, 2016

browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof we…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1693

Published Jun 5, 2016

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1692

Published Jun 5, 2016

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1691

Published Jun 5, 2016

Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibl…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1689

Published Jun 5, 2016

Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibl…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1,651-1,675 of 1,908 CVEsPage 67 of 77