Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 20 of 95
CVE-2016-3119P3MEDIUMCVSS 5.3v42.12016-03-26
CVE-2016-3119 [MEDIUM] CVE-2016-3119: The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB modul
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a pri
nvd
CVE-2020-25032P3HIGHCVSS 7.5v15.1v15.22020-08-31
CVE-2020-25032 [HIGH] CWE-22 CVE-2020-25032: An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ di
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
nvd
CVE-2015-8803P3CRITICALCVSS 9.8v42.12016-02-23
CVE-2015-8803 [CRITICAL] CWE-254 CVE-2015-8803: The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagati
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
nvd
CVE-2016-9427P3CRITICALCVSS 9.8v42.1v42.22016-12-12
CVE-2016-9427 [CRITICAL] CWE-119 CVE-2016-9427: Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
nvd
CVE-2019-18934P3HIGHCVSS 7.3v15.1v15.22019-11-19
CVE-2019-18934 [HIGH] CWE-78 CVE-2019-18934: Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code ex
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
nvd
CVE-2019-11035P3CRITICALCVSS 9.1v15.0v15.1+1 more2019-04-18
CVE-2019-11035 [CRITICAL] CWE-125 CVE-2019-11035: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.
nvd
CVE-2019-11034P3CRITICALCVSS 9.1v15.0v15.1+1 more2019-04-18
CVE-2019-11034 [CRITICAL] CWE-125 CVE-2019-11034: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
nvd
CVE-2017-18215P3CRITICALCVSS 9.8v42.32018-03-05
CVE-2017-18215 [CRITICAL] CWE-787 CVE-2017-18215: xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, le
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
nvd
CVE-2016-8866P3HIGHCVSS 8.8v42.1v42.22017-02-15
CVE-2016-8866 [HIGH] CVE-2016-8866: The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862.
nvd
CVE-2016-4954P3HIGHCVSS 7.5v42.12016-07-05
CVE-2016-4954 [HIGH] CWE-362 CVE-2016-4954: The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
nvd
CVE-2019-11039P3CRITICALCVSS 9.1v15.0v15.12019-06-19
CVE-2019-11039 [CRITICAL] CWE-125 CVE-2019-11039: Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.
Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.
nvd
CVE-2020-15205P3CRITICALCVSS 9.8v15.22020-09-25
CVE-2020-15205 [CRITICAL] CWE-119 CVE-2020-15205: In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of memory In the linked code snippet, all the binary strings after `ee ff` are contents from the memory stack. Si
nvd
CVE-2020-15963P3CRITICALCVSS 9.6v15.1v15.22020-09-21
CVE-2020-15963 [CRITICAL] CVE-2020-15963: Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an att
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2019-3863P3HIGHCVSS 8.8v15.0v42.32019-03-25
CVE-2019-3863 [HIGH] CWE-190 CVE-2019-3863: A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server c
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
nvd
CVE-2019-9640P3HIGHCVSS 7.5v15.0v15.1+1 more2019-03-09
CVE-2019-9640 [HIGH] CWE-125 CVE-2019-9640: An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x b
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.
nvd
CVE-2016-4539P3CRITICALCVSS 9.8v42.12016-05-22
CVE-2016-4539 [CRITICAL] CWE-119 CVE-2016-4539: The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other impact via crafted XML data in the second argument, leading to a parser level of zero.
nvd
CVE-2019-11730P3MEDIUMCVSS 6.5v15.0v15.12019-07-23
CVE-2019-11730 [MEDIUM] CVE-2019-11730: A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in comb
nvd
CVE-2019-16056P3HIGHCVSS 7.5v15.0v15.12019-09-06
CVE-2019-16056 [HIGH] CVE-2019-16056: An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address t
nvd
CVE-2020-15678P3HIGHCVSS 8.8v15.1v15.22020-10-01
CVE-2020-15678 [HIGH] CWE-416 CVE-2020-15678: When recursing through graphical layers while scrolling, an iterator may have become invalid, result
When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2019-5817P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5817 [HIGH] CWE-787 CVE-2019-5817: Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote at
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd