Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 26 of 95
CVE-2020-6450P3HIGHCVSS 8.8v15.12020-04-13
CVE-2020-6450 [HIGH] CWE-416 CVE-2020-6450: Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to pote
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6451P3HIGHCVSS 8.8v15.12020-04-13
CVE-2020-6451 [HIGH] CWE-416 CVE-2020-6451: Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to pote
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6377P3HIGHCVSS 8.8v15.12020-01-10
CVE-2020-6377 [HIGH] CWE-416 CVE-2020-6377: Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potenti
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5836P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5836 [HIGH] CWE-787 CVE-2019-5836: Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to po
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5807P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5807 [HIGH] CWE-787 CVE-2019-5807: Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pot
Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5828P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5828 [HIGH] CWE-416 CVE-2019-5828: Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote atta
Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2019-5813P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5813 [HIGH] CWE-416 CVE-2019-5813: Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentiall
Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-26117P3HIGHCVSS 8.1v15.22020-09-27
CVE-2020-26117 [HIGH] CWE-295 CVE-2020-26117: In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS c
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
nvd
CVE-2019-5829P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5829 [HIGH] CWE-190 CVE-2019-5829: Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacke
Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2019-5795P3HIGHCVSS 8.8v15.0v15.1+1 more2019-05-23
CVE-2019-5795 [HIGH] CWE-190 CVE-2019-5795: Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to poten
Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
nvd
CVE-2019-5792P3HIGHCVSS 8.8v15.0v15.1+1 more2019-05-23
CVE-2019-5792 [HIGH] CWE-190 CVE-2019-5792: Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to poten
Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
nvd
CVE-2020-12823P3CRITICALCVSS 9.8v15.1v15.22020-05-12
CVE-2020-12823 [CRITICAL] CWE-120 CVE-2020-12823: OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
nvd
CVE-2020-25219P3HIGHCVSS 7.5v15.1v15.22020-09-09
CVE-2020-25219 [HIGH] CWE-674 CVE-2020-25219: url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger unc
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
nvd
CVE-2018-10927P3HIGHCVSS 8.1v15.12018-09-04
CVE-2018-10927 [HIGH] CWE-20 CVE-2018-10927: A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
nvd
CVE-2020-10745P3HIGHCVSS 7.5v15.1v15.22020-07-07
CVE-2020-10745 [HIGH] CWE-400 CVE-2020-10745: A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way i
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest threat from this vulnerability is to system availability.
nvd
CVE-2020-13817P3HIGHCVSS 7.4v15.1v15.22020-06-04
CVE-2020-13817 [HIGH] CWE-330 CVE-2020-13817: ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of se
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instanc
nvd
CVE-2019-2859P3HIGHCVSS 8.8v15.0v15.12019-07-23
CVE-2019-2859 [HIGH] CVE-2019-2859: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnera
nvd
CVE-2019-12083P3HIGHCVSS 8.1v15.12019-05-13
CVE-2019-12083 [HIGH] CWE-125 CVE-2019-12083: The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method whi
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds w
nvd
CVE-2020-8620P3HIGHCVSS 7.5v15.1v15.22020-08-21
CVE-2020-8620 [HIGH] CWE-617 CVE-2020-8620: In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
nvd
CVE-2020-7062P3HIGHCVSS 7.5v15.12020-02-27
CVE-2020-7062 [HIGH] CWE-476 CVE-2020-7062: In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, whic
nvd