cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 28 of 95
CVE-2019-7573P3HIGHCVSS 8.8v15.0v42.32019-02-07
CVE-2019-7573 [HIGH] CWE-125 CVE-2019-7573: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).
nvd
CVE-2019-6486P3HIGHCVSS 8.2v15.02019-01-24
CVE-2019-6486 [HIGH] CWE-770 CVE-2019-6486: Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows a Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
nvd
CVE-2019-10895P3HIGHCVSS 7.5v15.0v15.1+1 more2019-04-09
CVE-2019-10895 [HIGH] CWE-125 CVE-2019-10895: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.
nvd
CVE-2016-1930P3CRITICALCVSS 9.8v42.12016-01-31
CVE-2016-1930 [CRITICAL] CWE-119 CVE-2016-1930: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-5395P3HIGHCVSS 8.8v15.12020-01-03
CVE-2020-5395 [HIGH] CWE-416 CVE-2020-5395: FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
nvd
CVE-2019-13298P3HIGHCVSS 8.8v15.0v15.12019-07-05
CVE-2019-13298 [HIGH] CWE-787 CVE-2019-13298: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixel ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.
nvd
CVE-2020-5496P3HIGHCVSS 8.8v15.12020-01-03
CVE-2020-5496 [HIGH] CWE-787 CVE-2020-5496: FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesa FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.
nvd
CVE-2019-6251P3HIGHCVSS 8.1v15.0v42.32019-01-14
CVE-2019-6251 [HIGH] CVE-2019-6251: WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
nvd
CVE-2016-9843P3CRITICALCVSS 9.8v42.1v42.22017-05-23
CVE-2016-9843 [CRITICAL] CVE-2016-9843: The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unsp The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
nvd
CVE-2020-11080P3HIGHCVSS 7.5v15.12020-06-03
CVE-2020-11080 [HIGH] CWE-707 CVE-2020-11080: In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of se In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vul
nvd
CVE-2019-17498P3HIGHCVSS 8.1v15.12019-10-21
CVE-2019-17498 [HIGH] CWE-190 CVE-2019-17498: In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer over In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when
nvd
CVE-2020-12422P3HIGHCVSS 8.8v15.1v15.22020-07-09
CVE-2020-12422 [HIGH] CWE-787 CVE-2020-12422: In non-standard configurations, a JPEG image created by JavaScript could have caused an internal var In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
nvd
CVE-2020-24606P3HIGHCVSS 7.5v15.1v15.22020-08-24
CVE-2020-24606 [HIGH] CWE-667 CVE-2020-24606: Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consumi Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles
nvd
CVE-2016-1697P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1697 [HIGH] CWE-284 CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used i The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2019-11740P3HIGHCVSS 8.8v15.0v15.12019-09-27
CVE-2019-11740 [HIGH] CWE-787 CVE-2019-11740: Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird
nvd
CVE-2019-9003P3HIGHCVSS 7.5v15.02019-02-22
CVE-2019-9003 [HIGH] CWE-416 CVE-2019-9003: In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-a In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.
nvd
CVE-2019-5791P3HIGHCVSS 8.8v15.0v15.1+1 more2019-05-23
CVE-2019-5791 [HIGH] CWE-125 CVE-2019-5791: Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2016-1672P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1672 [HIGH] CWE-254 CVE-2016-1672: The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extensio The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1675P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1675 [HIGH] CWE-284 CVE-2016-1675: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
nvd
CVE-2020-6454P3HIGHCVSS 8.8v15.12020-04-13
CVE-2020-6454 [HIGH] CWE-416 CVE-2020-6454: Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convince Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
Opensuse Leap vulnerabilities | cvebase