Skip to main content

Vendor archive

opensuse CVEs

Beta · best-effort

3,282 CVEs tagged to vendor opensuse427 Critical, 1,220 High, 1,398 Medium, 237 Low, 0 Unrated.

CVE-2014-0480

Published Aug 26, 2014

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5149

Published Aug 22, 2014

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcp…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5146

Published Aug 22, 2014

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3594

Published Aug 22, 2014

Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows r…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-5274

Published Aug 22, 2014

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbit…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3528

Published Aug 19, 2014

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier…

CVSS 4.0 · Medium

CVE-2014-4987

Published Jul 20, 2014

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4002

Published Jul 3, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,601-2,625 of 3,282 CVEsPage 105 of 132