cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 33 of 95
CVE-2019-11494P3HIGHCVSS 7.5v15.0v15.12019-05-08
CVE-2019-11494 [HIGH] CWE-476 CVE-2019-11494: In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the c In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
nvd
CVE-2019-5163P3HIGHCVSS 7.5v15.12019-12-03
CVE-2019-5163 [HIGH] CWE-306 CVE-2019-5163: An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-l An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.
nvd
CVE-2015-8874P3HIGHCVSS 7.5v42.12016-05-16
CVE-2015-8874 [HIGH] CWE-119 CVE-2015-8874: Stack consumption vulnerability in GD in PHP before 5.6.12 allows remote attackers to cause a denial Stack consumption vulnerability in GD in PHP before 5.6.12 allows remote attackers to cause a denial of service via a crafted imagefilltoborder call.
nvd
CVE-2020-17367P3HIGHCVSS 7.8v15.22020-08-11
CVE-2020-17367 [HIGH] CWE-88 CVE-2020-17367: Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, wh Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
nvd
CVE-2018-19865P3HIGHCVSS 7.5v15.02018-12-05
CVE-2018-19865 [HIGH] CWE-532 CVE-2018-19865: A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.
nvd
CVE-2017-9104P3CRITICALCVSS 9.8v15.12020-06-18
CVE-2017-9104 [CRITICAL] CWE-400 CVE-2017-9104: An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
nvd
CVE-2018-16412P3HIGHCVSS 8.8v15.02018-09-03
CVE-2018-16412 [HIGH] CWE-125 CVE-2018-16412: ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlo ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.
nvd
CVE-2016-1238P3HIGHCVSS 7.8v15.02016-08-02
CVE-2016-1238 [HIGH] CWE-264 CVE-2016-1238: (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan
nvd
CVE-2018-1128P3HIGHCVSS 7.5v15.02018-07-10
CVE-2018-1128 [HIGH] CWE-294 CVE-2018-1128: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulner It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, lumino
nvd
CVE-2019-3692P3HIGHCVSS 7.8v15.12020-01-24
CVE-2019-3692 [HIGH] CWE-59 CVE-2019-3692: The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local at The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.
nvd
CVE-2020-8014P3HIGHCVSS 7.8v15.12020-06-29
CVE-2020-8014 [HIGH] CWE-61 CVE-2020-8014: A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE Tumbleweed kopano-spamd versions prior to 10.
nvd
CVE-2020-14376P3HIGHCVSS 7.8v15.1v15.22020-09-30
CVE-2020-14376 [HIGH] CWE-120 CVE-2020-14376: A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking w A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-8933P3HIGHCVSS 7.8v15.1v15.22020-06-22
CVE-2020-8933 [HIGH] CWE-276 CVE-2020-8933: A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allo A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and filesystems. Within an lxc container, it is possible to attach the host OS fil
nvd
CVE-2020-8907P3HIGHCVSS 7.8v15.1v15.22020-06-22
CVE-2020-8907 [HIGH] CWE-276 CVE-2020-8907: A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allo A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" group, an attacker with this role is able to run docker and mount the host OS. Within docker, it is possible to modify t
nvd
CVE-2023-32182P3HIGHCVSS 7.8v15.52023-09-19
CVE-2023-32182 [HIGH] CWE-59 CVE-2023-32182: A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux En A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1; SUSE Linux Enterprise High Performa
nvd
CVE-2020-14375P3HIGHCVSS 7.8v15.1v15.22020-09-30
CVE-2020-14375 [HIGH] CWE-367 CVE-2020-14375: A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, an A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest threat from this vulnerability is to
nvd
CVE-2020-0432P3HIGHCVSS 7.8v15.1v15.22020-09-17
CVE-2020-0432 [HIGH] CWE-190 CVE-2020-0432: In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143560807
nvd
CVE-2019-19880P3HIGHCVSS 7.5v15.12019-12-18
CVE-2019-19880 [HIGH] CWE-476 CVE-2019-19880: exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer deref exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
nvd
CVE-2019-19949P3CRITICALCVSS 9.1v15.12019-12-24
CVE-2019-19949 [CRITICAL] CWE-125 CVE-2019-19949: In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
nvd
CVE-2019-19923P3HIGHCVSS 7.5v15.12019-12-24
CVE-2019-19923 [HIGH] CWE-476 CVE-2019-19923: flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
nvd
Opensuse Leap vulnerabilities | cvebase