Skip to main content

Vendor archive

opensuse CVEs

Beta · best-effort

3,282 CVEs tagged to vendor opensuse427 Critical, 1,220 High, 1,398 Medium, 237 Low, 0 Unrated.

CVE-2014-0564

Published Oct 15, 2014

Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
21.9

CVE-2014-4043

Published Oct 6, 2014

The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3637

Published Sep 22, 2014

D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial o…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3985

Published Sep 11, 2014

The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3169

Published Aug 27, 2014

Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a den…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3168

Published Aug 27, 2014

Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly hav…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-2528

Published Aug 26, 2014

kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) charac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2527

Published Aug 26, 2014

kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) charac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0483

Published Aug 26, 2014

The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represen…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0482

Published Aug 26, 2014

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the con…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,576-2,600 of 3,282 CVEsPage 104 of 132