cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 32 of 95
CVE-2020-10995P3HIGHCVSS 7.5v15.12020-05-19
CVE-2020-10995 [HIGH] CWE-400 CVE-2020-10995: PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplific PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritative name servers. The attack uses a crafted reply by an authoritative name server to amplify the result
nvd
CVE-2015-7210P3HIGHCVSS 7.5v42.12015-12-16
CVE-2015-7210 [HIGH] CVE-2015-7210: Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering attempted use of a data channel that has been closed by a WebRTC function.
nvd
CVE-2019-12529P3MEDIUMCVSS 5.9v15.0v15.12019-07-11
CVE-2019-12529 [MEDIUM] CWE-125 CVE-2019-12529: An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. W An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over the input and checking its table. The length is then used to start decodin
nvd
CVE-2016-2347P3HIGHCVSS 7.8v42.12017-04-21
CVE-2016-2347 [HIGH] CWE-190 CVE-2016-2347: Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3. Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
nvd
CVE-2020-25866P3HIGHCVSS 7.5v15.1v15.22020-10-06
CVE-2020-25866 [HIGH] CWE-476 CVE-2020-25866: In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dere In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.
nvd
CVE-2020-11741P3HIGHCVSS 8.8v15.12020-04-14
CVE-2020-11741 [HIGH] CWE-909 CVE-2020-11741: An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active prof An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the administrator, the xenoprof code uses the standard Xen shared ring structure. U
nvd
CVE-2016-1944P3CRITICALCVSS 9.8v42.12016-01-31
CVE-2016-1944 [CRITICAL] CWE-119 CVE-2016-1944: The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might a The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2020-6575P3HIGHCVSS 8.3v15.1v15.22020-09-21
CVE-2020-6575 [HIGH] CWE-362 CVE-2020-6575: Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised t Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-8622P3MEDIUMCVSS 6.5v15.1v15.22020-08-21
CVE-2020-8622 [MEDIUM] CWE-617 CVE-2020-8622: In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the se
nvd
CVE-2016-9958P3HIGHCVSS 7.8v42.22017-04-12
CVE-2016-9958 [HIGH] CWE-119 CVE-2016-9958: game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
nvd
CVE-2018-10911P3HIGHCVSS 7.5v15.12018-09-04
CVE-2018-10911 [HIGH] CWE-190 CVE-2018-10911: A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key lengt A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
nvd
CVE-2017-6318P3HIGHCVSS 7.5v42.12017-03-20
CVE-2017-6318 [HIGH] CWE-200 CVE-2017-6318: saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a c saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
nvd
CVE-2021-41819P3HIGHCVSS 7.5v15.22022-01-01
CVE-2021-41819 [HIGH] CWE-565 CVE-2021-41819: CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affe CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
nvd
CVE-2019-13304P3HIGHCVSS 7.8v15.0v15.12019-07-05
CVE-2019-13304 [HIGH] CWE-787 CVE-2019-13304: ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
nvd
CVE-2019-13306P3HIGHCVSS 7.8v15.0v15.12019-07-05
CVE-2019-13306 [HIGH] CWE-193 CVE-2019-13306: ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
nvd
CVE-2020-12865P3HIGHCVSS 8.0v15.1v15.22020-06-24
CVE-2020-12865 [HIGH] CWE-787 CVE-2020-12865: A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
nvd
CVE-2019-9854P3HIGHCVSS 7.8v15.0v15.12019-09-06
CVE-2019-9854 [HIGH] CVE-2019-9854: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a d
nvd
CVE-2016-9957P3HIGHCVSS 7.8v42.22017-04-12
CVE-2016-9957 [HIGH] CWE-119 CVE-2016-9957: Stack-based buffer overflow in game-music-emu before 0.6.1. Stack-based buffer overflow in game-music-emu before 0.6.1.
nvd
CVE-2019-9852P3HIGHCVSS 7.8v15.0v15.12019-08-15
CVE-2019-9852 [HIGH] CWE-116 CVE-2019-9852: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to
nvd
CVE-2019-7548P3HIGHCVSS 7.8v15.0v15.12019-02-06
CVE-2019-7548 [HIGH] CWE-89 CVE-2019-7548: SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
nvd
Opensuse Leap vulnerabilities | cvebase