cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 25 of 95
CVE-2019-13619P3HIGHCVSS 7.5v15.0v15.12019-07-17
CVE-2019-13619 [HIGH] CWE-119 CVE-2019-13619: In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and relate In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.
nvd
CVE-2020-11793P3HIGHCVSS 8.8v15.12020-04-17
CVE-2020-11793 [HIGH] CWE-416 CVE-2020-11793: A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted we A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).
nvd
CVE-2019-13308P3HIGHCVSS 8.8v15.0v15.12019-07-05
CVE-2019-13308 [HIGH] CWE-787 CVE-2019-13308: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage. ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.
nvd
CVE-2016-4540P3CRITICALCVSS 9.8v42.12016-05-22
CVE-2016-4540 [CRITICAL] CVE-2016-4540: The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x bef The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
nvd
CVE-2016-4541P3CRITICALCVSS 9.8v42.12016-05-22
CVE-2016-4541 [CRITICAL] CVE-2016-4541: The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x befo The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
nvd
CVE-2020-12723P3HIGHCVSS 7.5v15.12020-06-05
CVE-2020-12723 [HIGH] CWE-120 CVE-2020-12723: regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
nvd
CVE-2016-4542P3CRITICALCVSS 9.8v42.12016-05-22
CVE-2016-4542 [CRITICAL] CWE-119 CVE-2016-4542: The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
nvd
CVE-2019-11506P3HIGHCVSS 8.8v15.0v15.1+1 more2019-04-24
CVE-2019-11506 [HIGH] CWE-787 CVE-2019-11506: In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer over In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.
nvd
CVE-2018-15518P3HIGHCVSS 8.8v42.32018-12-26
CVE-2018-15518 [HIGH] CWE-415 CVE-2018-15518: QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially cra QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
nvd
CVE-2016-4537P3CRITICALCVSS 9.8v42.12016-05-22
CVE-2016-4537 [CRITICAL] CWE-20 CVE-2016-4537: The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x befo The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
nvd
CVE-2018-12085P3HIGHCVSS 8.8v15.02018-06-09
CVE-2018-12085 [HIGH] CVE-2018-12085: Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTab Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
nvd
CVE-2018-11683P3HIGHCVSS 8.8v15.02018-06-04
CVE-2018-11683 [HIGH] CVE-2018-11683: Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTab Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
nvd
CVE-2016-1946P3CRITICALCVSS 9.8v42.12016-01-31
CVE-2016-1946 [CRITICAL] CWE-119 CVE-2016-1946: The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox bef The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.
nvd
CVE-2016-8687P3HIGHCVSS 7.5v42.22017-02-15
CVE-2016-8687 [HIGH] CWE-119 CVE-2016-8687: Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows re Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a crafted non-printable multibyte character in a filename.
nvd
CVE-2020-6455P3HIGHCVSS 8.8v15.12020-04-13
CVE-2020-6455 [HIGH] CWE-125 CVE-2020-6455: Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to pot Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-17008P3HIGHCVSS 8.8v15.12020-01-08
CVE-2019-17008 [HIGH] CWE-416 CVE-2019-17008: When using nested workers, a use-after-free could occur during worker destruction. This resulted in When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2018-20548P3HIGHCVSS 8.8v15.02018-12-28
CVE-2018-20548 [HIGH] CWE-119 CVE-2018-20548: There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data.
nvd
CVE-2019-5816P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5816 [HIGH] CWE-664 CVE-2019-5816: Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.
nvd
CVE-2020-15656P3HIGHCVSS 8.8v15.22020-08-10
CVE-2020-15656 [HIGH] CWE-843 CVE-2020-15656: JIT optimizations involving the Javascript arguments object could confuse later optimizations. This JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-6530P3HIGHCVSS 8.8v15.1v15.22020-07-22
CVE-2020-6530 [HIGH] CWE-787 CVE-2020-6530: Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an att Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
Opensuse Leap vulnerabilities | cvebase