Skip to main content

Vendor archive

opensuse CVEs

Beta · best-effort

3,282 CVEs tagged to vendor opensuse427 Critical, 1,220 High, 1,398 Medium, 237 Low, 0 Unrated.

CVE-2014-3494

Published Jul 1, 2014

kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4165

Published Jun 16, 2014

Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a list action to plugins/rrdPlugin.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3153

Published Jun 7, 2014

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain pri…

CVSS 7.8 · High
evidence mentions
20
Buzz score
71.0
KEV listed

CVE-2014-3470

Published Jun 5, 2014

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allow…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
24.1

CVE-2014-0221

Published Jun 5, 2014

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2014-3968

Published Jun 5, 2014

The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3967

Published Jun 5, 2014

The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to caus…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1934

Published May 8, 2014

tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2913

Published May 7, 2014

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7336

Published May 7, 2014

The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows lo…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0198

Published May 6, 2014

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
24.1
Showing 2,626-2,650 of 3,282 CVEsPage 106 of 132