cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 38 of 95
CVE-2019-20839P3HIGHCVSS 7.5v15.22020-06-17
CVE-2019-20839 [HIGH] CWE-120 CVE-2019-20839: libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filenam libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
nvd
CVE-2020-12663P3HIGHCVSS 7.5v15.1v15.22020-05-19
CVE-2020-12663 [HIGH] CWE-835 CVE-2020-12663: Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
nvd
CVE-2018-14553P3HIGHCVSS 7.5v15.12020-02-11
CVE-2018-14553 [HIGH] CWE-476 CVE-2018-14553: gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attack gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
nvd
CVE-2019-3836P3HIGHCVSS 7.5v15.02019-04-01
CVE-2019-3836 [HIGH] CWE-456 CVE-2019-3836: It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer acc It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
nvd
CVE-2018-20547P3HIGHCVSS 8.1v15.02018-12-28
CVE-2018-20547 [HIGH] CWE-119 CVE-2018-20547: There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99. There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.
nvd
CVE-2020-13164P3HIGHCVSS 7.5v15.1v15.22020-05-19
CVE-2020-13164 [HIGH] CWE-674 CVE-2020-13164: In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. Th In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.
nvd
CVE-2021-41817P3HIGHCVSS 7.5v15.22022-01-01
CVE-2021-41817 [HIGH] CWE-1333 CVE-2021-41817: Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
nvd
CVE-2020-9428P3HIGHCVSS 7.5v15.12020-02-27
CVE-2020-9428 [HIGH] CWE-125 CVE-2020-9428: In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. Thi In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.
nvd
CVE-2020-15466P3HIGHCVSS 7.5v15.1v15.22020-07-05
CVE-2020-15466 [HIGH] CWE-835 CVE-2020-15466: In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed i In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.
nvd
CVE-2019-14235P3HIGHCVSS 7.5v15.12019-08-02
CVE-2019-14235 [HIGH] CWE-674 CVE-2019-14235: An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4 An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.
nvd
CVE-2019-1010006P3HIGHCVSS 7.8v15.0v15.12019-07-15
CVE-2019-1010006 [HIGH] CWE-190 CVE-2019-1010006: Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The comp Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.
nvd
CVE-2020-14400P3HIGHCVSS 7.5v15.1v15.22020-06-17
CVE-2020-14400 [HIGH] CVE-2020-14400: An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_ An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
nvd
CVE-2020-14399P3HIGHCVSS 7.5v15.1v15.22020-06-17
CVE-2020-14399 [HIGH] CVE-2020-14399: An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_ An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
nvd
CVE-2019-10691P3HIGHCVSS 7.5v15.02019-04-24
CVE-2019-10691 [HIGH] CVE-2019-10691: The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication s The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
nvd
CVE-2015-8078P3HIGHCVSS 7.5v42.12015-12-03
CVE-2015-8078 [HIGH] CVE-2015-8078: Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2. Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
nvd
CVE-2020-6097P3HIGHCVSS 7.5v15.22020-09-10
CVE-2020-6097 [HIGH] CWE-617 CVE-2020-6097: An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0. An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.
nvd
CVE-2020-14422P3MEDIUMCVSS 5.9v15.1v15.22020-06-18
CVE-2020-14422 [MEDIUM] CWE-330 CVE-2020-14422: Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IP Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entri
nvd
CVE-2018-19490P3HIGHCVSS 7.8v15.02018-11-23
CVE-2018-19490 [HIGH] CWE-787 CVE-2018-19490: An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a h An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.
nvd
CVE-2018-19491P3HIGHCVSS 7.8v15.02018-11-23
CVE-2018-19491 [HIGH] CWE-119 CVE-2018-19491: An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buf An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.
nvd
CVE-2018-19492P3HIGHCVSS 7.8v15.02018-11-23
CVE-2018-19492 [HIGH] CWE-119 CVE-2018-19492: An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a bu An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.
nvd
Opensuse Leap vulnerabilities | cvebase