Vulnerabilities > Opensuse > High

DATE CVE VULNERABILITY TITLE RISK
2019-09-06 CVE-2019-9458 Use After Free vulnerability in multiple products
In the Android kernel in the video driver there is a use after free due to a race condition.
local
high complexity
google opensuse CWE-416
7.0
2019-09-06 CVE-2019-9854 Path Traversal vulnerability in multiple products
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc.
7.8
2019-09-06 CVE-2019-16056 An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. 7.5
2019-09-04 CVE-2017-18595 Double Free vulnerability in multiple products
An issue was discovered in the Linux kernel before 4.14.11.
local
low complexity
linux opensuse CWE-415
7.8
2019-09-04 CVE-2019-15917 Use After Free vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.0.5.
local
high complexity
linux debian opensuse CWE-416
7.0
2019-09-03 CVE-2019-14817 Incorrect Authorization vulnerability in multiple products
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions.
7.8
2019-09-03 CVE-2019-14811 Incorrect Authorization vulnerability in multiple products
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions.
7.8
2019-09-02 CVE-2019-15847 Insufficient Entropy vulnerability in multiple products
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator.
network
low complexity
gnu opensuse CWE-331
7.5
2019-08-25 CVE-2019-15538 Resource Exhaustion vulnerability in multiple products
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9.
7.5
2019-08-20 CVE-2019-10086 Deserialization of Untrusted Data vulnerability in multiple products
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects.
7.3