Product:

Backports_sle

(Opensuse)
Date Id Summary Products Score Patch Annotated
2020-05-21 CVE-2020-6488 Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Debian_linux, Fedora, Chrome, Backports_sle, Leap 4.3
2020-05-21 CVE-2020-6489 Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page. Debian_linux, Fedora, Chrome, Backports_sle, Leap 4.3
2020-05-21 CVE-2020-6490 Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page. Debian_linux, Fedora, Chrome, Backports_sle, Leap 4.3
2020-05-21 CVE-2020-6491 Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name. Debian_linux, Fedora, Chrome, Backports_sle, Leap 6.5
2020-05-26 CVE-2020-13614 An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification. Axel, Fedora, Backports_sle, Leap 5.9
2020-06-03 CVE-2020-13379 The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault. Fedora, Grafana, E\-Series_performance_analyzer, Backports_sle, Leap 8.2
2020-06-08 CVE-2020-13696 An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the existence of arbitrary files and to trigger an open on arbitrary files with mode O_RDWR. To achieve this, relative path components need to be added to the device path, as demonstrated... Ubuntu_linux, Debian_linux, Fedora, Xawtv, Backports_sle, Leap 4.4
2020-06-30 CVE-2020-15396 In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root. Fedora, Hylafax\+, Hylafax_enterprise, Backports_sle, Leap 7.8
2020-07-22 CVE-2020-6510 Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Debian_linux, Fedora, Chrome, Backports_sle, Leap 7.8
2020-07-22 CVE-2020-6511 Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Debian_linux, Fedora, Chrome, Backports_sle, Leap 6.5