Vulnerabilities > Opensuse > Leap > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-07-23 | CVE-2019-11728 | Exposure of Resource to Wrong Sphere vulnerability in multiple products The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. | 4.7 |
2019-07-23 | CVE-2019-11725 | When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. | 6.5 |
2019-07-23 | CVE-2019-11724 | Incorrect Authorization vulnerability in multiple products Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. | 6.1 |
2019-07-23 | CVE-2019-11721 | The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. | 6.5 |
2019-07-23 | CVE-2019-11720 | Cross-site Scripting vulnerability in multiple products Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. | 6.1 |
2019-07-23 | CVE-2019-11718 | Injection vulnerability in multiple products Activity Stream can display content from sent from the Snippet Service website. | 5.3 |
2019-07-23 | CVE-2019-11717 | Improper Encoding or Escaping of Output vulnerability in multiple products A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. | 5.3 |
2019-07-17 | CVE-2019-13626 | Out-of-bounds Read vulnerability in multiple products SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c. | 6.5 |
2019-07-17 | CVE-2019-9849 | LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. | 4.3 |
2019-07-11 | CVE-2019-12529 | Out-of-bounds Read vulnerability in multiple products An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. | 5.9 |