VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
> Opensuse
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2019-07-23
CVE-2019-2762
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities).
network
low complexity
oracle
canonical
opensuse
debian
redhat
mcafee
hp
5.3
5.3
2019-07-23
CVE-2019-2745
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security).
local
high complexity
oracle
debian
canonical
opensuse
mcafee
hp
5.1
5.1
2019-07-23
CVE-2019-2740
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML).
network
low complexity
oracle
canonical
mariadb
redhat
fedoraproject
opensuse
6.5
6.5
2019-07-23
CVE-2019-2737
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth).
network
low complexity
oracle
canonical
mariadb
fedoraproject
opensuse
4.9
4.9
2019-07-23
CVE-2019-9811
Injection vulnerability in multiple products
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation.
network
high complexity
mozilla
debian
novell
opensuse
CWE-74
8.3
8.3
2019-07-23
CVE-2019-11730
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed.
network
low complexity
mozilla
debian
opensuse
suse
6.5
6.5
2019-07-23
CVE-2019-11728
Exposure of Resource to Wrong Sphere vulnerability in multiple products
The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded.
network
low complexity
mozilla
opensuse
CWE-668
4.7
4.7
2019-07-23
CVE-2019-11725
When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections.
network
low complexity
mozilla
opensuse
6.5
6.5
2019-07-23
CVE-2019-11724
Incorrect Authorization vulnerability in multiple products
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site.
network
low complexity
mozilla
opensuse
CWE-863
6.1
6.1
2019-07-23
CVE-2019-11723
Origin Validation Error vulnerability in multiple products
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context.
network
low complexity
mozilla
opensuse
CWE-346
7.5
7.5
«
Previous
1
2
...
117
118
119
(current)
120
121
...
226
227
»
Next