Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 23 of 95
CVE-2016-1673P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1673 [HIGH] CVE-2016-1673: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2019-17596P3HIGHCVSS 7.5v15.0v15.12019-10-24
CVE-2019-17596 [HIGH] CWE-436 CVE-2019-17596: Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic conta
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
nvd
CVE-2020-6496P3HIGHCVSS 8.8v15.12020-06-03
CVE-2020-6496 [HIGH] CWE-416 CVE-2020-6496: Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-9286P3HIGHCVSS 8.8v42.32018-03-01
CVE-2017-9286 [HIGH] CVE-2017-9286: The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have al
The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
nvd
CVE-2020-16008P3HIGHCVSS 8.8v15.1v15.22020-11-03
CVE-2020-16008 [HIGH] CWE-787 CVE-2020-16008: Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
nvd
CVE-2020-7040P3HIGHCVSS 8.1v15.12020-01-21
CVE-2020-7040 [HIGH] CWE-59 CVE-2020-7040: storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
nvd
CVE-2020-13398P3HIGHCVSS 8.3v15.12020-05-22
CVE-2020-13398 [HIGH] CWE-787 CVE-2020-13398: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
nvd
CVE-2020-8164P3HIGHCVSS 7.5v15.1v15.22020-06-19
CVE-2020-8164 [HIGH] CWE-502 CVE-2020-8164: A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which c
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
nvd
CVE-2020-2902P3HIGHCVSS 8.8v15.12020-04-15
CVE-2020-2902 [HIGH] CWE-787 CVE-2020-2902: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
nvd
CVE-2020-14352P3HIGHCVSS 8.0v15.22020-08-30
CVE-2020-14352 [HIGH] CWE-22 CVE-2020-14352: A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in
nvd
CVE-2015-8804P3CRITICALCVSS 9.8v42.12016-02-23
CVE-2015-8804 [CRITICAL] CWE-254 CVE-2015-8804: x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
nvd
CVE-2020-14593P3HIGHCVSS 7.4v15.1v15.22020-07-15
CVE-2020-14593 [HIGH] CVE-2020-14593: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful atta
nvd
CVE-2020-10804P3HIGHCVSS 8.0v15.12020-03-22
CVE-2020-10804 [HIGH] CWE-89 CVE-2020-10804: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retr
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with
nvd
CVE-2020-25039P3HIGHCVSS 8.1v15.1v15.22020-09-16
CVE-2020-25039 [HIGH] CWE-668 CVE-2020-25039: Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fak
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
nvd
CVE-2019-8322P3HIGHCVSS 7.5v15.0v15.12019-06-17
CVE-2019-8322 [HIGH] CWE-74 CVE-2019-8322: An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the c
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.
nvd
CVE-2019-11005P3CRITICALCVSS 9.8v15.0v42.32019-04-08
CVE-2019-11005 [CRITICAL] CWE-787 CVE-2019-11005: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function S
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.
nvd
CVE-2014-3462P3HIGHCVSS 7.5v42.1v42.22017-08-07
CVE-2014-3462 [HIGH] CWE-200 CVE-2014-3462: The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensiti
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
nvd
CVE-2020-11077P3HIGHCVSS 7.5v15.1v15.22020-05-22
CVE-2020-11077 [HIGH] CVE-2020-11077: In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing
In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connections and the client adds another request in via HTTP pipelining, the proxy may mistake it as the first request's body. Puma, however, would see it as two requests,
nvd
CVE-2019-14817P3HIGHCVSS 7.8v15.0v15.12019-09-03
CVE-2019-14817 [HIGH] CWE-648 CVE-2019-14817: A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures w
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
nvd
CVE-2020-25643P3HIGHCVSS 7.2v15.1v15.22020-10-06
CVE-2020-25643 [HIGH] CWE-20 CVE-2020-25643: A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corru
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well
nvd