cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 30 of 95
CVE-2019-11709P3CRITICALCVSS 9.8v15.0v15.12019-07-23
CVE-2019-11709 [CRITICAL] CWE-787 CVE-2019-11709: Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 6
nvd
CVE-2020-11868P3HIGHCVSS 7.5v15.1v15.22020-04-17
CVE-2020-11868 [HIGH] CWE-346 CVE-2020-11868: ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenti ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
nvd
CVE-2019-7524P3HIGHCVSS 7.8v15.0v42.32019-03-28
CVE-2019-7524 [HIGH] CWE-119 CVE-2019-7524: In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.
nvd
CVE-2019-9215P3CRITICALCVSS 9.8v15.0v15.1+1 more2019-02-28
CVE-2019-9215 [CRITICAL] CVE-2019-9215: In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizat In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
nvd
CVE-2020-4067P3HIGHCVSS 7.5v15.22020-06-29
CVE-2020-4067 [HIGH] CWE-665 CVE-2020-4067: In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initial In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This
nvd
CVE-2016-5116P3CRITICALCVSS 9.1v42.12016-08-07
CVE-2016-5116 [CRITICAL] CWE-119 CVE-2016-5116: gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x co gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.
nvd
CVE-2017-6594P3HIGHCVSS 7.5v42.2v42.32017-08-28
CVE-2017-6594 [HIGH] CWE-295 CVE-2017-6594: The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath po The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.
nvd
CVE-2019-20637P3HIGHCVSS 7.5v15.12020-04-08
CVE-2019-20637 [HIGH] CWE-212 CVE-2019-20637: An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x b An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with
nvd
CVE-2020-8022P3HIGHCVSS 7.8v15.12020-06-29
CVE-2020-8022 [HIGH] CWE-276 CVE-2020-8022: A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux En
nvd
CVE-2019-7221P3HIGHCVSS 7.8v15.02019-03-21
CVE-2019-7221 [HIGH] CWE-416 CVE-2019-7221: The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
nvd
CVE-2020-14004P3HIGHCVSS 7.8v15.1v15.22020-06-12
CVE-2020-14004 [HIGH] CWE-59 CVE-2020-14004: An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the i An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged
nvd
CVE-2017-17806P3HIGHCVSS 7.8v42.22017-12-20
CVE-2017-17806 [HIGH] CWE-787 CVE-2017-17806: The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executi
nvd
CVE-2019-20787P3CRITICALCVSS 9.8v15.12020-04-22
CVE-2019-20787 [CRITICAL] CWE-190 CVE-2019-20787: Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size. Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size.
nvd
CVE-2020-14349P3HIGHCVSS 7.1v15.1v15.22020-08-24
CVE-2020-14349 [HIGH] CVE-2020-14349: It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly san It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
nvd
CVE-2017-17740P3HIGHCVSS 7.5v15.0v15.12017-12-18
CVE-2017-17740 [HIGH] CWE-119 CVE-2017-17740: contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memb contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.
nvd
CVE-2019-19926P3HIGHCVSS 7.5v15.12019-12-23
CVE-2019-19926 [HIGH] CVE-2019-19926: multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated b multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
nvd
CVE-2019-11006P3CRITICALCVSS 9.1v15.0v42.32019-04-08
CVE-2019-11006 [CRITICAL] CWE-125 CVE-2019-11006: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function R In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.
nvd
CVE-2019-16775P3MEDIUMCVSS 6.5v15.12019-12-13
CVE-2019-16775 [MEDIUM] CWE-61 CVE-2019-16775: Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible fo Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files
nvd
CVE-2018-16227P3HIGHCVSS 7.5v15.0v15.12019-10-03
CVE-2018-16227 [HIGH] CWE-125 CVE-2018-16227: The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.
nvd
CVE-2019-19925P3HIGHCVSS 7.5v15.12019-12-24
CVE-2019-19925 [HIGH] CWE-434 CVE-2019-19925: zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
nvd
Opensuse Leap vulnerabilities | cvebase