VendorsopenSUSEleap42.2
Vulnerabilities

openSUSE Leap 42.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

87CVEs
CVE-2017-13087
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
Published 2017-10-17 · Modified
5.3EPSS 0.017
CVE-2015-7542
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
Published 2019-12-03 · Modified
5.3EPSS 0.004
CVE-2016-7170
The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing a DEFINE_CURSOR svga command.
Published 2016-12-10 · Modified
4.4EPSS 0.004
CVE-2016-9104
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds access.
Published 2016-12-09 · Modified
4.4EPSS 0.004
CVE-2017-5930
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
Published 2017-03-20 · Modified
3.5EPSS 0.150
CVE-2016-4983
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
Published 2019-11-05 · Modified
3.3EPSS 0.004
CVE-2016-1000002
gdm3 3.14.2 and possibly later has an information leak before screen lock
Published 2019-11-05 · Modified
2.4EPSS 0.005
← Prev3 / 3