cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 35 of 95
CVE-2016-9597P3HIGHCVSS 7.5v42.12018-07-30
CVE-2016-9597 [HIGH] CVE-2016-9597: It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actua It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
nvd
CVE-2015-8126P3HIGHCVSS 7.5v42.12015-11-13
CVE-2015-8126 [HIGH] CWE-120 CVE-2015-8126: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1. Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value
nvd
CVE-2015-7212P3HIGHCVSS 7.5v42.12015-12-16
CVE-2015-7212 [HIGH] CWE-189 CVE-2015-7212: Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a graphics operation that requires a large texture allocation.
nvd
CVE-2019-20372P3MEDIUMCVSS 5.3v15.12020-01-09
CVE-2019-20372 [MEDIUM] CWE-444 CVE-2019-20372: NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demon NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
nvd
CVE-2019-1010180P3HIGHCVSS 7.8v15.0v15.12019-07-24
CVE-2019-1010180 [HIGH] CWE-125 CVE-2019-1010180: GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: De GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet.
nvd
CVE-2019-8325P3HIGHCVSS 7.5v15.0v15.12019-06-17
CVE-2019-8325 [HIGH] CWE-74 CVE-2019-8325: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
nvd
CVE-2019-8321P3HIGHCVSS 7.5v15.0v15.12019-06-17
CVE-2019-8321 [HIGH] CWE-88 CVE-2019-8321: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
nvd
CVE-2015-8077P3HIGHCVSS 7.5v42.12015-12-03
CVE-2015-8077 [HIGH] CVE-2015-8077: Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2. Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
nvd
CVE-2019-14233P3HIGHCVSS 7.5v15.12019-08-02
CVE-2019-14233 [HIGH] CWE-400 CVE-2019-14233: An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4 An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large sequences of nested incomplete HTML entities.
nvd
CVE-2020-12672P3HIGHCVSS 7.5v15.12020-05-06
CVE-2020-12672 [HIGH] CWE-787 CVE-2020-12672: GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
nvd
CVE-2019-13305P3HIGHCVSS 7.8v15.0v15.12019-07-05
CVE-2019-13305 [HIGH] CWE-193 CVE-2019-13305: ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.
nvd
CVE-2019-13050P3HIGHCVSS 7.5v15.0v15.12019-06-29
CVE-2019-13050 [HIGH] CWE-295 CVE-2019-13050: Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG thr Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.
nvd
CVE-2015-8618P3HIGHCVSS 7.5v42.12016-01-27
CVE-2015-8618 [HIGH] CWE-200 CVE-2015-8618: The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propag The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
nvd
CVE-2016-1572P3HIGHCVSS 8.4v42.12016-01-22
CVE-2016-1572 [HIGH] CWE-269 CVE-2016-1572: mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, whi mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
nvd
CVE-2019-11499P3HIGHCVSS 7.5v15.0v15.12019-05-08
CVE-2019-11499 [HIGH] CVE-2019-11499: In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.
nvd
CVE-2019-13106P3HIGHCVSS 7.8v15.0v15.12019-08-06
CVE-2019-13106 [HIGH] CWE-787 CVE-2019-13106: Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted e Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
nvd
CVE-2020-25862P3HIGHCVSS 7.5v15.1v15.22020-10-06
CVE-2020-25862 [HIGH] CWE-354 CVE-2020-25862: In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. Th In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
nvd
CVE-2020-2601P3MEDIUMCVSS 6.8v15.12020-01-15
CVE-2020-2601 [MEDIUM] CVE-2020-2601: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulner
nvd
CVE-2017-9108P3HIGHCVSS 7.5v15.12020-06-18
CVE-2017-9108 [HIGH] CWE-119 CVE-2017-9108: An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() would have done. Without this fix, adnshost may read and process one byte beyond the buffer, perhaps crashin
nvd
CVE-2020-10648P3HIGHCVSS 7.8v15.22020-03-19
CVE-2020-10648 [HIGH] CWE-20 CVE-2020-10648: Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently bo Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
nvd
Opensuse Leap vulnerabilities | cvebase