Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 31 of 95
CVE-2019-13297P3HIGHCVSS 8.8v15.0v15.12019-07-05
CVE-2019-13297 [HIGH] CWE-125 CVE-2019-13297: ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThre
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.
nvd
CVE-2019-13295P3HIGHCVSS 8.8v15.0v15.12019-07-05
CVE-2019-13295 [HIGH] CWE-125 CVE-2019-13295: ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThre
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.
nvd
CVE-2016-1974P3HIGHCVSS 8.8v42.12016-03-13
CVE-2016-1974 [HIGH] CWE-119 CVE-2016-1974: The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x be
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
nvd
CVE-2019-7638P3HIGHCVSS 8.8v15.0v42.32019-02-08
CVE-2019-7638 [HIGH] CWE-125 CVE-2019-7638: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
nvd
CVE-2015-7202P3CRITICALCVSS 10.0v42.12015-12-16
CVE-2015-7202 [CRITICAL] CWE-119 CVE-2015-7202: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2019-7574P3HIGHCVSS 8.8v15.0v42.32019-02-07
CVE-2019-7574 [HIGH] CWE-125 CVE-2019-7574: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
nvd
CVE-2019-7572P3HIGHCVSS 8.8v15.0v42.32019-02-07
CVE-2019-7572 [HIGH] CWE-125 CVE-2019-7572: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_AD
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
nvd
CVE-2019-20907P3HIGHCVSS 7.5v15.1v15.22020-07-13
CVE-2019-20907 [HIGH] CWE-835 CVE-2019-20907: In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
nvd
CVE-2020-12417P3HIGHCVSS 8.8v15.1v15.22020-07-09
CVE-2020-12417 [HIGH] CWE-617 CVE-2020-12417: Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier,
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2019-10896P3HIGHCVSS 7.5v15.0v15.1+1 more2019-04-09
CVE-2019-10896 [HIGH] CWE-787 CVE-2019-10896: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was add
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.
nvd
CVE-2019-10894P3HIGHCVSS 7.5v15.0v15.1+1 more2019-04-09
CVE-2019-10894 [HIGH] CWE-617 CVE-2019-10894: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.
nvd
CVE-2019-17012P3HIGHCVSS 8.8v15.12020-01-08
CVE-2019-17012 [HIGH] CWE-787 CVE-2019-17012: Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of t
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2016-5159P3HIGHCVSS 8.8v42.12016-09-11
CVE-2016-5159 [HIGH] CWE-190 CVE-2016-5159: Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Wi
Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during opj_aligned_malloc calls in dw
nvd
CVE-2020-12420P3HIGHCVSS 8.8v15.1v15.22020-07-09
CVE-2020-12420 [HIGH] CWE-362 CVE-2020-12420: When trying to connect to a STUN server, a race condition could have caused a use-after-free of a po
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2016-1676P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1676 [HIGH] CWE-284 CVE-2016-1676: extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2020-16845P3HIGHCVSS 7.5v15.1v15.22020-08-06
CVE-2020-16845 [HIGH] CWE-835 CVE-2020-16845: Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarin
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
nvd
CVE-2019-5820P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5820 [HIGH] CWE-190 CVE-2019-5820: Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pote
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-5821P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5821 [HIGH] CWE-190 CVE-2019-5821: Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pote
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-5806P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5806 [HIGH] CWE-190 CVE-2019-5806: Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attack
Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5811P3HIGHCVSS 8.8v15.0v15.1+1 more2019-06-27
CVE-2019-5811 [HIGH] CVE-2019-5811: Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd