cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 16 of 95
CVE-2019-17042P3CRITICALCVSS 9.8v15.0v15.12019-10-07
CVE-2019-17042 [CRITICAL] CWE-20 CVE-2019-17042: An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflo An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMs
nvd
CVE-2019-6690P3HIGHCVSS 7.5v15.02019-03-21
CVE-2019-6690 [HIGH] CWE-20 CVE-2019-6690: python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext tha python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
nvd
CVE-2019-11627P3CRITICALCVSS 9.8v15.0v42.32019-04-30
CVE-2019-11627 [CRITICAL] CWE-78 CVE-2019-11627: gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
nvd
CVE-2016-1935P3HIGHCVSS 8.8v42.12016-01-31
CVE-2016-1935 [HIGH] CWE-119 CVE-2016-1935: Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x be Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
nvd
CVE-2020-15917P3CRITICALCVSS 9.8v15.1v15.22020-07-23
CVE-2020-15917 [CRITICAL] CVE-2020-15917: common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STAR common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
nvd
CVE-2019-9639P3HIGHCVSS 7.5v15.0v15.1+1 more2019-03-09
CVE-2019-9639 [HIGH] CWE-908 CVE-2019-9639: An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x b An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
nvd
CVE-2019-18421P3HIGHCVSS 7.5v15.02019-10-31
CVE-2019-18421 [HIGH] CWE-362 CVE-2019-18421: An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privile An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoid using shadow pagetables for PV guests, Xen exposes the actual hardware pagetables to the guest. In or
nvd
CVE-2019-2602P3HIGHCVSS 7.5v15.0v42.32019-04-23
CVE-2019-2602 [HIGH] CWE-400 CVE-2019-2602: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2016-9841P3CRITICALCVSS 9.8v42.1v42.22017-05-23
CVE-2016-9841 [CRITICAL] CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by levera inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2016-3982P3HIGHCVSS 8.8v42.12016-04-13
CVE-2016-3982 [HIGH] CWE-119 CVE-2016-3982: Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.
nvd
CVE-2016-5770P3CRITICALCVSS 9.8v42.12016-08-07
CVE-2016-5770 [CRITICAL] CVE-2016-5770: Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.
nvd
CVE-2018-11440P3HIGHCVSS 8.8v15.02018-05-25
CVE-2018-11440 [HIGH] CWE-787 CVE-2018-11440: Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTab Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.
nvd
CVE-2019-8324P3HIGHCVSS 8.8v15.0v15.12019-06-17
CVE-2019-8324 [HIGH] CWE-94 CVE-2019-8324: An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line nam An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
nvd
CVE-2018-18356P3HIGHCVSS 8.8v15.02018-12-11
CVE-2018-18356 [HIGH] CWE-190 CVE-2018-18356: An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0 An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-10906P3HIGHCVSS 8.6v15.0v42.32019-04-07
CVE-2019-10906 [HIGH] CVE-2019-10906: In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
nvd
CVE-2020-6513P3HIGHCVSS 8.8v15.1v15.22020-07-22
CVE-2020-6513 [HIGH] CWE-787 CVE-2020-6513: Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to p Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-13082P3HIGHCVSS 8.1v42.2v42.32017-10-17
CVE-2017-13082 [HIGH] CWE-323 CVE-2017-13082: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwi Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2020-6517P3HIGHCVSS 8.8v15.1v15.22020-07-22
CVE-2020-6517 [HIGH] CWE-787 CVE-2020-6517: Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-13249P3HIGHCVSS 8.8v15.12020-05-20
CVE-2020-13249 [HIGH] CVE-2020-13249: libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
nvd
CVE-2020-6523P3HIGHCVSS 8.8v15.1v15.22020-07-22
CVE-2020-6523 [HIGH] CWE-190 CVE-2020-6523: Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pote Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Opensuse Leap vulnerabilities | cvebase