Vulnerabilities > Opensuse

DATE CVE VULNERABILITY TITLE RISK
2013-03-07 CVE-2013-2480 Denial of Service vulnerability in Wireshark RTPS And RTPS2 Dissectors
The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
low complexity
debian opensuse wireshark
3.3
2013-03-07 CVE-2013-2479 Denial of Service vulnerability in Wireshark MPLS Echo Dissector
The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via invalid Sub-tlv data.
low complexity
wireshark opensuse
3.3
2013-03-07 CVE-2013-2478 Numeric Errors vulnerability in multiple products
The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.
low complexity
debian opensuse wireshark CWE-189
3.3
2013-03-07 CVE-2013-2477 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The CSN.1 dissector in Wireshark 1.8.x before 1.8.6 does not properly manage function pointers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
low complexity
wireshark opensuse CWE-119
3.3
2013-03-07 CVE-2013-2476 Resource Management Errors vulnerability in multiple products
The dissect_hartip function in epan/dissectors/packet-hartip.c in the HART/IP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a packet with a header that is too short.
low complexity
wireshark opensuse CWE-399
6.1
2013-03-07 CVE-2013-2475 Denial of Service vulnerability in Wireshark TCP Dissector
The TCP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
low complexity
wireshark opensuse
3.3
2013-03-05 CVE-2013-1415 Null Pointer Dereference vulnerability in multiple products
The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 and 1.11.x before 1.11.1 does not properly handle errors during extraction of fields from an X.509 certificate, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed KRB5_PADATA_PK_AS_REQ AS-REQ request.
network
low complexity
mit opensuse CWE-476
5.0
2013-02-19 CVE-2013-0784 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
network
mozilla opensuse canonical
critical
9.3
2013-02-19 CVE-2013-0783 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. 9.3
2013-02-19 CVE-2013-0782 Out-Of-Bounds Write vulnerability in multiple products
Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via unspecified vectors.
9.3