Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 37 of 95
CVE-2013-6393P3MEDIUMCVSS 6.8v42.12014-02-06
CVE-2013-6393 [MEDIUM] CWE-119 CVE-2013-6393: The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cas
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
nvd
CVE-2019-10903P3HIGHCVSS 7.5v15.0v15.1+1 more2019-04-09
CVE-2019-10903 [HIGH] CWE-125 CVE-2019-10903: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. T
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.
nvd
CVE-2019-10901P3HIGHCVSS 7.5v15.0v15.1+1 more2019-04-09
CVE-2019-10901 [HIGH] CWE-476 CVE-2019-10901: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was ad
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.
nvd
CVE-2019-13299P3HIGHCVSS 8.8v15.0v15.12019-07-05
CVE-2019-13299 [HIGH] CWE-125 CVE-2019-13299: ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixe
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel.
nvd
CVE-2016-2790P3HIGHCVSS 8.8v42.12016-03-13
CVE-2016-2790 [HIGH] CWE-19 CVE-2016-2790: The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
nvd
CVE-2016-2795P3HIGHCVSS 8.8v42.12016-03-13
CVE-2016-2795 [HIGH] CWE-19 CVE-2016-2795: The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefo
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
nvd
CVE-2019-13303P3HIGHCVSS 8.8v15.0v15.12019-07-05
CVE-2019-13303 [HIGH] CWE-125 CVE-2019-13303: ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeIma
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.
nvd
CVE-2018-14522P3HIGHCVSS 8.8v15.0v42.32018-07-23
CVE-2018-14522 [HIGH] CWE-119 CVE-2018-14522: An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pit
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.
nvd
CVE-2016-1234P3HIGHCVSS 7.5v42.12016-06-01
CVE-2016-1234 [HIGH] CWE-119 CVE-2016-1234: Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, whe
Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.
nvd
CVE-2016-5152P3HIGHCVSS 8.8v42.12016-09-11
CVE-2016-5152 [HIGH] CWE-190 CVE-2016-5152: Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFi
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.
nvd
CVE-2020-12426P3HIGHCVSS 8.8v15.1v15.22020-07-09
CVE-2020-12426 [HIGH] CWE-787 CVE-2020-12426: Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of
Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 78.
nvd
CVE-2019-7635P3HIGHCVSS 8.1v15.0v15.1+1 more2019-02-08
CVE-2019-7635 [HIGH] CWE-125 CVE-2019-7635: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
nvd
CVE-2016-5158P3HIGHCVSS 8.8v42.12016-09-11
CVE-2016-5158 [HIGH] CWE-190 CVE-2016-5158: Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium
Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.
nvd
CVE-2019-20010P3HIGHCVSS 8.8v15.12019-12-27
CVE-2019-20010 [HIGH] CWE-416 CVE-2019-20010: An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
nvd
CVE-2020-12416P3HIGHCVSS 8.8v15.1v15.22020-07-09
CVE-2020-12416 [HIGH] CWE-362 CVE-2020-12416: A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink,
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
nvd
CVE-2019-11735P3HIGHCVSS 8.8v15.0v15.12019-09-27
CVE-2019-11735 [HIGH] CWE-787 CVE-2019-11735: Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2020-12243P3HIGHCVSS 7.5v15.12020-04-28
CVE-2020-12243 [HIGH] CWE-674 CVE-2020-12243: In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
nvd
CVE-2018-16451P3HIGHCVSS 7.5v15.0v15.12019-10-03
CVE-2018-16451 [HIGH] CWE-125 CVE-2018-16451: The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILS
The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.
nvd
CVE-2020-24659P3HIGHCVSS 7.5v15.1v15.22020-09-04
CVE-2020-24659 [HIGH] CWE-476 CVE-2020-24659: An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls_deinit function is called after detecting a handshake f
nvd
CVE-2020-13113P3HIGHCVSS 8.2v15.12020-05-21
CVE-2020-13113 [HIGH] CWE-908 CVE-2020-13113: An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote hand
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
nvd