Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 14 of 95
CVE-2016-1000104P3HIGHCVSS 8.8v42.12019-12-03
CVE-2016-1000104 [HIGH] CWE-20 CVE-2016-1000104: A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
nvd
CVE-2019-13565P3HIGHCVSS 7.5v15.0v15.12019-07-26
CVE-2019-13565 [HIGH] CVE-2019-13565: An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session en
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is re
nvd
CVE-2020-8201P3HIGHCVSS 7.4v15.22020-09-18
CVE-2020-8201 [HIGH] CWE-444 CVE-2020-8201: Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due t
nvd
CVE-2019-15691P3HIGHCVSS 7.2v15.12019-12-26
CVE-2019-15691 [HIGH] CWE-825 CVE-2019-15691: TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorr
TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack variable, which has been already freed during the process of stack unwinding. Exploitation of this vulnerability could potentiall
nvd
CVE-2019-7443P3HIGHCVSS 8.1v15.0v42.32019-05-07
CVE-2019-7443 [HIGH] CWE-20 CVE-2019-7443: KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as ro
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity
nvd
CVE-2019-9499P3HIGHCVSS 8.1v15.12019-04-17
CVE-2019-9499 [HIGH] CWE-346 CVE-2019-9499: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missi
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supp
nvd
CVE-2019-9898P3CRITICALCVSS 9.8v15.02019-03-21
CVE-2019-9898 [CRITICAL] CWE-330 CVE-2019-9898: Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
nvd
CVE-2015-8866P3CRITICALCVSS 9.6v42.12016-05-22
CVE-2015-8866 [CRITICAL] CVE-2015-8866: ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isol
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
nvd
CVE-2019-3861P3CRITICALCVSS 9.1v15.0v42.32019-03-25
CVE-2019-3861 [CRITICAL] CWE-125 CVE-2019-3861: An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padd
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
nvd
CVE-2019-17455P3CRITICALCVSS 9.8v15.12019-10-10
CVE-2019-17455 [CRITICAL] CWE-125 CVE-2019-17455: Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, an
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.
nvd
CVE-2016-1629P3CRITICALCVSS 9.8v42.12016-02-21
CVE-2016-1629 [CRITICAL] CWE-264 CVE-2016-1629: Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy an
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
nvd
CVE-2020-12268P3CRITICALCVSS 9.8v15.12020-04-27
CVE-2020-12268 [CRITICAL] CWE-787 CVE-2020-12268: jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflo
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
nvd
CVE-2019-6438P3CRITICALCVSS 9.8v15.02019-01-31
CVE-2019-6438 [CRITICAL] CVE-2019-6438: SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
nvd
CVE-2019-1353P3CRITICALCVSS 9.8v15.12020-01-24
CVE-2019-1353 [CRITICAL] CWE-22 CVE-2019-1353: An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.1
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active.
nvd
CVE-2017-9109P3CRITICALCVSS 9.8v15.12020-06-18
CVE-2017-9109 [CRITICAL] CWE-119 CVE-2017-9109: An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first R
An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that case the answer data structure (o
nvd
CVE-2020-10878P3HIGHCVSS 8.6v15.12020-06-05
CVE-2020-10878 [HIGH] CWE-190 CVE-2020-10878: Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
nvd
CVE-2019-5051P3HIGHCVSS 8.8v15.0v15.12019-07-03
CVE-2019-5051 [HIGH] CWE-390 CVE-2019-5051: An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
nvd
CVE-2018-1088P3HIGHCVSS 8.1v15.12018-04-18
CVE-2018-1088 [HIGH] CWE-266 CVE-2018-1088: A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
nvd
CVE-2018-18335P3HIGHCVSS 8.8v15.02018-12-11
CVE-2018-18335 [HIGH] CWE-787 CVE-2018-18335: Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to pot
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6466P3CRITICALCVSS 9.6v15.12020-05-21
CVE-2020-6466 [CRITICAL] CWE-416 CVE-2020-6466: Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had com
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd