cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 36 of 95
CVE-2019-9628P3HIGHCVSS 7.5v15.0v42.32019-04-11
CVE-2019-9628 [HIGH] CWE-755 CVE-2019-9628: The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Servi The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
nvd
CVE-2017-5335P3HIGHCVSS 7.5v42.1v42.22017-03-24
CVE-2017-5335 [HIGH] CWE-125 CVE-2017-5335: The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3 The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
nvd
CVE-2020-4031P3HIGHCVSS 7.5v15.12020-06-22
CVE-2020-4031 [HIGH] CWE-416 CVE-2020-4031: In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
nvd
CVE-2016-0753P3MEDIUMCVSS 5.3v42.12016-02-16
CVE-2016-0753 [MEDIUM] CVE-2016-0753: Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
nvd
CVE-2016-5178P3CRITICALCVSS 9.8v42.12017-05-23
CVE-2016-5178 [CRITICAL] CWE-20 CVE-2016-5178: Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2019-6778P3HIGHCVSS 7.8v15.0v42.32019-03-21
CVE-2019-6778 [HIGH] CWE-787 CVE-2019-6778: In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow. In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
nvd
CVE-2019-19728P3HIGHCVSS 7.5v15.12020-01-13
CVE-2019-19728 [HIGH] CWE-269 CVE-2019-19728: SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
nvd
CVE-2019-18898P3HIGHCVSS 7.8v15.12020-01-23
CVE-2019-18898 [HIGH] CWE-59 CVE-2019-18898: UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterpris UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
nvd
CVE-2018-12477P3HIGHCVSS 7.5v15.0v42.32018-10-09
CVE-2018-12477 [HIGH] CWE-93 CVE-2018-12477: A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attack A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versions prior to d6244245dda5367767efc989446fe4b5e4609cce.
nvd
CVE-2019-18897P3HIGHCVSS 7.8v15.12020-03-02
CVE-2019-18897 [HIGH] CWE-59 CVE-2019-18897: A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterp A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linu
nvd
CVE-2020-15396P3HIGHCVSS 7.8v15.1v15.22020-06-30
CVE-2020-15396 [HIGH] CWE-362 CVE-2020-15396: In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user- In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
nvd
CVE-2019-6128P3HIGHCVSS 8.8v15.02019-01-11
CVE-2019-6128 [HIGH] CWE-401 CVE-2019-6128: The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rg The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
nvd
CVE-2020-8026P3HIGHCVSS 7.8v15.1v15.22020-08-07
CVE-2020-8026 [HIGH] CWE-276 CVE-2020-8026: A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUS A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 an
nvd
CVE-2020-15567P3HIGHCVSS 7.8v15.1v15.22020-07-07
CVE-2020-15567 [HIGH] CWE-362 CVE-2020-15567: An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or c An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-atomic bitfield writes. Depending on the compiler version and optimisation
nvd
CVE-2019-19953P3CRITICALCVSS 9.1v15.12019-12-24
CVE-2019-19953 [CRITICAL] CWE-125 CVE-2019-19953: In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function E In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
nvd
CVE-2016-1953P3HIGHCVSS 8.8v42.12016-03-13
CVE-2016-1953 [HIGH] CWE-119 CVE-2016-1953: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.
nvd
CVE-2019-0220P3MEDIUMCVSS 5.3v15.0v42.32019-06-11
CVE-2019-0220 [MEDIUM] CWE-706 CVE-2019-0220: A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a reques A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.
nvd
CVE-2020-1711P3MEDIUMCVSS 6.0v15.12020-02-11
CVE-2020-1711 [MEDIUM] CWE-122 CVE-2020-1711: An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU version An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of
nvd
CVE-2019-8936P3HIGHCVSS 7.5v15.0v42.32019-05-15
CVE-2019-8936 [HIGH] CWE-476 CVE-2019-8936: NTP through 4.2.8p12 has a NULL Pointer Dereference. NTP through 4.2.8p12 has a NULL Pointer Dereference.
nvd
CVE-2018-19870P3HIGHCVSS 8.8v15.02018-12-26
CVE-2018-19870 [HIGH] CWE-476 CVE-2018-19870: An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
nvd
Opensuse Leap vulnerabilities | cvebase