Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 12 of 95
CVE-2019-5737P3HIGHCVSS 7.5v42.32019-03-28
CVE-2019-5737 [HIGH] CVE-2019-5737: In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.1
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitig
nvd
CVE-2016-7447P3CRITICALCVSS 9.8v42.12017-02-06
CVE-2016-7447 [CRITICAL] CWE-119 CVE-2016-7447: Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
nvd
CVE-2020-12693P3HIGHCVSS 8.1v15.1v15.22020-05-21
CVE-2020-12693 [HIGH] CVE-2020-12693: Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
nvd
CVE-2018-10923P3HIGHCVSS 8.1v15.12018-09-04
CVE-2018-10923 [HIGH] CWE-20 CVE-2018-10923: It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a g
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
nvd
CVE-2020-17353P3CRITICALCVSS 9.8v15.22020-08-05
CVE-2020-17353 [CRITICAL] CVE-2020-17353: scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe i
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
nvd
CVE-2014-0221P3MEDIUMCVSS 4.3v42.12014-06-05
CVE-2014-0221 [MEDIUM] CVE-2014-0221: The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m,
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.
nvd
CVE-2017-9103P3CRITICALCVSS 9.8v15.12020-06-18
CVE-2017-9103 [CRITICAL] CWE-119 CVE-2017-9103: An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__f
An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects of the contents of some of its
nvd
CVE-2019-9637P3HIGHCVSS 7.5v42.32019-03-09
CVE-2019-9637 [HIGH] CWE-264 CVE-2019-9637: An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to th
An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.
nvd
CVE-2019-5060P3HIGHCVSS 8.8v15.0v15.12019-07-31
CVE-2019-5060 [HIGH] CWE-190 CVE-2019-5060: An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately ending in code execution. An attacker
nvd
CVE-2017-5337P3CRITICALCVSS 9.8v42.1v42.22017-03-24
CVE-2017-5337 [CRITICAL] CWE-119 CVE-2017-5337: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
nvd
CVE-2020-3865P3HIGHCVSS 8.8v15.12020-02-27
CVE-2020-3865 [HIGH] CWE-787 CVE-2020-3865: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-11036P3CRITICALCVSS 9.1v15.0v15.1+1 more2019-05-03
CVE-2019-11036 [CRITICAL] CWE-126 CVE-2019-11036: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
nvd
CVE-2020-15207P3CRITICALCVSS 9.0v15.22020-09-25
CVE-2020-15207 [CRITICAL] CWE-119 CVE-2020-15207: In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` to convert negative values to positive indices. However, the only check that the converted index is now valid is only present in debug builds. If the `DCHECK` does not trigger, then code execution mov
nvd
CVE-2020-15900P3CRITICALCVSS 9.8v15.1v15.22020-07-28
CVE-2020-15900 [CRITICAL] CWE-191 CVE-2020-15900: A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard Post
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b
nvd
CVE-2019-12528P3HIGHCVSS 7.5v15.12020-02-04
CVE-2019-12528 [HIGH] CVE-2019-12528: An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure o
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
nvd
CVE-2019-17041P3CRITICALCVSS 9.8v15.0v15.12019-10-07
CVE-2019-17041 [CRITICAL] CWE-787 CVE-2019-17041: An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a
An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do not satisfy this constraint. If the string does not match, then the varia
nvd
CVE-2019-6470P3HIGHCVSS 7.5v15.0v15.12019-11-01
CVE-2019-6470 [HIGH] CVE-2019-6470: There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when o
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND lib
nvd
CVE-2019-5010P3HIGHCVSS 7.5v15.12019-10-31
CVE-2019-5010 [HIGH] CWE-476 CVE-2019-5010: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org P
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
nvd
CVE-2014-9852P3CRITICALCVSS 9.8v42.12017-03-17
CVE-2014-9852 [CRITICAL] CWE-913 CVE-2014-9852: distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remot
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
nvd
CVE-2016-7141P3HIGHCVSS 7.5v42.12016-10-03
CVE-2016-7141 [HIGH] CVE-2016-7141: curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at run
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
nvd