cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 22 of 95
CVE-2020-25645P3HIGHCVSS 7.5v15.1v15.22020-10-13
CVE-2020-25645 [HIGH] CWE-319 CVE-2020-25645: A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoint A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidenti
nvd
CVE-2019-19951P3CRITICALCVSS 9.8v15.12019-12-24
CVE-2019-19951 [CRITICAL] CWE-787 CVE-2019-19951: In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function Im In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
nvd
CVE-2018-20843P3HIGHCVSS 7.5v15.0v15.12019-06-24
CVE-2018-20843 [HIGH] CWE-611 CVE-2018-20843: In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colo In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
nvd
CVE-2020-10663P3HIGHCVSS 7.5v15.12020-04-28
CVE-2020-10663 [HIGH] CVE-2020-10663: The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 t The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the
nvd
CVE-2015-8948P3HIGHCVSS 7.5v42.12016-09-07
CVE-2015-8948 [HIGH] CWE-125 CVE-2015-8948: idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
nvd
CVE-2020-6471P3CRITICALCVSS 9.6v15.12020-05-21
CVE-2020-6471 [CRITICAL] CWE-276 CVE-2020-6471: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2020-25829P3HIGHCVSS 7.5v15.1v15.22020-10-16
CVE-2020-25829 [HIGH] CVE-2020-25829: An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3 An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (
nvd
CVE-2016-4544P3CRITICALCVSS 9.8v42.12016-05-22
CVE-2016-4544 [CRITICAL] CWE-119 CVE-2016-4544: The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
nvd
CVE-2019-13300P3HIGHCVSS 8.8v15.0v15.12019-07-05
CVE-2019-13300 [HIGH] CWE-787 CVE-2019-13300: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImage ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
nvd
CVE-2016-2828P3HIGHCVSS 8.8v42.12016-06-13
CVE-2016-2828 [HIGH] CVE-2016-2828: Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
nvd
CVE-2019-11505P3HIGHCVSS 8.8v15.0v15.1+1 more2019-04-24
CVE-2019-11505 [HIGH] CWE-787 CVE-2019-11505: In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overf In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.
nvd
CVE-2016-4538P3CRITICALCVSS 9.8v42.12016-05-22
CVE-2016-4538 [CRITICAL] CWE-20 CVE-2016-4538: The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x befo The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted cal
nvd
CVE-2020-15659P3HIGHCVSS 8.8v15.1v15.22020-08-10
CVE-2020-15659 [HIGH] CWE-787 CVE-2020-15659: Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1,
nvd
CVE-2018-20545P3HIGHCVSS 8.8v15.02018-12-28
CVE-2018-20545 [HIGH] CWE-190 CVE-2018-20545: There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
nvd
CVE-2019-12921P3MEDIUMCVSS 6.5v15.12020-03-18
CVE-2019-12921 [MEDIUM] CWE-77 CVE-2019-12921: In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitra In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
nvd
CVE-2019-5827P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5827 [HIGH] CWE-190 CVE-2019-5827: Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attac Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15673P3HIGHCVSS 8.8v15.1v15.22020-10-01
CVE-2020-15673 [HIGH] CWE-416 CVE-2020-15673: Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of t Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2019-5822P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5822 [HIGH] CVE-2019-5822: Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attac Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2018-20549P3HIGHCVSS 8.8v15.02018-12-28
CVE-2018-20549 [HIGH] CWE-119 CVE-2018-20549: There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.bet There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.
nvd
CVE-2016-1674P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1674 [HIGH] CVE-2016-1674: The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
Opensuse Leap vulnerabilities | cvebase