Vulnerabilities
Vulnerable Software
Opensuse:  Security Vulnerabilities
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
CVSS Score
7.8
EPSS Score
0.015
Published
2019-12-20
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
CVSS Score
7.8
EPSS Score
0.016
Published
2019-12-20
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
CVSS Score
9.8
EPSS Score
0.665
Published
2019-12-20
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison.
CVSS Score
6.3
EPSS Score
0.037
Published
2019-12-18
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
CVSS Score
7.5
EPSS Score
0.069
Published
2019-12-18
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.
CVSS Score
7.5
EPSS Score
0.027
Published
2019-12-17
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
CVSS Score
5.5
EPSS Score
0.005
Published
2019-12-17
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.
CVSS Score
5.8
EPSS Score
0.014
Published
2019-12-16
duplicity 0.6.24 has improper verification of SSL certificates
CVSS Score
7.5
EPSS Score
0.009
Published
2019-12-13
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
CVSS Score
4.4
EPSS Score
0.004
Published
2019-12-13


Contact Us

Shodan ® - All rights reserved