Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 27 of 95
CVE-2018-16402P3CRITICALCVSS 9.8v15.0v15.12018-09-03
CVE-2018-16402 [CRITICAL] CWE-415 CVE-2018-16402: libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
nvd
CVE-2019-8323P3HIGHCVSS 7.5v15.0v15.12019-06-17
CVE-2019-8323 [HIGH] CWE-74 CVE-2019-8323: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_respon
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
nvd
CVE-2016-1866P3HIGHCVSS 8.1v42.12016-04-12
CVE-2016-1866 [HIGH] CWE-284 CVE-2016-1866: Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows ma
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
nvd
CVE-2020-12066P3HIGHCVSS 7.5v15.12020-04-22
CVE-2020-12066 [HIGH] CWE-20 CVE-2020-12066: CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
nvd
CVE-2016-5739P3HIGHCVSS 7.5v42.12016-07-03
CVE-2016-5739 [HIGH] CWE-200 CVE-2016-5739: The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.
nvd
CVE-2016-4342P3HIGHCVSS 8.8v42.12016-05-22
CVE-2016-4342 [HIGH] CWE-119 CVE-2016-4342: ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles ze
ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) TAR, (2) ZIP, or (3) PHAR archive.
nvd
CVE-2015-8805P3CRITICALCVSS 9.8v42.12016-02-23
CVE-2015-8805 [CRITICAL] CVE-2015-8805: The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagati
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
nvd
CVE-2015-8614P3HIGHCVSS 7.3v42.12016-04-11
CVE-2015-8614 [HIGH] CWE-119 CVE-2015-8614: Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjis
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.
nvd
CVE-2014-2525P3MEDIUMCVSS 6.8v42.12014-03-28
CVE-2014-2525 [MEDIUM] CWE-119 CVE-2014-2525: Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allo
Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.
nvd
CVE-2020-10757P3HIGHCVSS 7.8v15.12020-06-09
CVE-2020-10757 [HIGH] CWE-119 CVE-2020-10757: A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pa
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
nvd
CVE-2020-15811P3MEDIUMCVSS 6.5v15.1v15.22020-09-02
CVE-2020-15811 [MEDIUM] CWE-697 CVE-2020-15811: An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation,
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content
nvd
CVE-2019-10162P3HIGHCVSS 7.5v15.0v15.12019-07-30
CVE-2019-10162 [HIGH] CWE-400 CVE-2019-10162: A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowi
A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/A
nvd
CVE-2020-1772P3HIGHCVSS 7.5v15.1v15.22020-03-27
CVE-2020-1772 [HIGH] CWE-155 CVE-2020-1772: It's possible to craft Lost Password requests with wildcards in the Token value, which allows attack
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
nvd
CVE-2019-14835P3HIGHCVSS 7.8v15.0v15.12019-09-17
CVE-2019-14835 [HIGH] CWE-120 CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their pr
nvd
CVE-2016-2796P3HIGHCVSS 8.8v42.12016-03-13
CVE-2016-2796 [HIGH] CWE-119 CVE-2016-2796: Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
nvd
CVE-2020-8903P3HIGHCVSS 7.8v15.1v15.22020-06-22
CVE-2020-8903 [HIGH] CWE-276 CVE-2020-8903: A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allo
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal. Using the DHCP XID, it is then possible
nvd
CVE-2019-11008P3HIGHCVSS 8.8v15.0v42.32019-04-08
CVE-2019-11008 [HIGH] CWE-787 CVE-2019-11008: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function Wr
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
nvd
CVE-2022-45153P3HIGHCVSS 7.8v15.42023-02-15
CVE-2022-45153 [HIGH] CWE-276 CVE-2022-45153: An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SA
nvd
CVE-2016-6262P3HIGHCVSS 7.5v42.12016-09-07
CVE-2016-6262 [HIGH] CVE-2016-6262: idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by rea
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
nvd
CVE-2019-7577P3HIGHCVSS 8.8v15.0v42.32019-02-07
CVE-2019-7577 [HIGH] CWE-125 CVE-2019-7577: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_Lo
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
nvd