Vulnerabilities
Vulnerable Software
Opensuse:  Security Vulnerabilities
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
CVSS Score
7.8
EPSS Score
0.014
Published
2020-05-11
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
CVSS Score
7.8
EPSS Score
0.013
Published
2020-05-11
exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
CVSS Score
5.5
EPSS Score
0.005
Published
2020-05-09
An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.
CVSS Score
5.5
EPSS Score
0.007
Published
2020-05-09
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
CVSS Score
5.5
EPSS Score
0.005
Published
2020-05-09
There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.
CVSS Score
6.5
EPSS Score
0.004
Published
2020-05-08
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
CVSS Score
6.5
EPSS Score
0.027
Published
2020-05-06
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
CVSS Score
7.5
EPSS Score
0.035
Published
2020-05-06
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
CVSS Score
7.5
EPSS Score
0.029
Published
2020-05-06
An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea.
CVSS Score
7.8
EPSS Score
0.004
Published
2020-05-05


Contact Us

Shodan ® - All rights reserved