cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 41 of 95
CVE-2020-6609P3HIGHCVSS 8.8v15.12020-01-08
CVE-2020-6609 [HIGH] CWE-125 CVE-2020-6609: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c. GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
nvd
CVE-2016-1678P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1678 [HIGH] CWE-119 CVE-2016-1678: objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not pro objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2020-7039P3MEDIUMCVSS 5.6v15.12020-01-16
CVE-2020-7039 [MEDIUM] CWE-787 CVE-2020-7039: tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated b tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
nvd
CVE-2016-1681P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1681 [HIGH] CWE-119 CVE-2016-1681: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
nvd
CVE-2015-7221P3CRITICALCVSS 10.0v42.12015-12-16
CVE-2015-7221 [CRITICAL] CWE-119 CVE-2015-7221: Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox b Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.
nvd
CVE-2019-20014P3HIGHCVSS 8.8v15.12019-12-27
CVE-2019-20014 [HIGH] CWE-415 CVE-2019-20014: An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c. An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
nvd
CVE-2016-4049P3HIGHCVSS 7.5v42.12016-05-23
CVE-2016-4049 [HIGH] CWE-20 CVE-2016-4049: The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dum The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a large BGP packet.
nvd
CVE-2015-8080P3HIGHCVSS 7.5v42.12016-04-13
CVE-2015-8080 [HIGH] CWE-190 CVE-2015-8080: Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x befor Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stac
nvd
CVE-2019-9811P3HIGHCVSS 8.3v15.0v15.12019-07-23
CVE-2019-9811 [HIGH] CWE-74 CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malic As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2015-7203P3CRITICALCVSS 10.0v42.12015-12-16
CVE-2015-7203 [CRITICAL] CWE-119 CVE-2015-7203: Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontL Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font-family name.
nvd
CVE-2018-20615P3HIGHCVSS 7.5v15.02019-03-21
CVE-2018-20615 [HIGH] CWE-125 CVE-2018-20615: An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
nvd
CVE-2016-3959P3HIGHCVSS 7.5v42.12016-05-23
CVE-2016-3959 [HIGH] CWE-20 CVE-2016-3959: The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
nvd
CVE-2019-7578P3HIGHCVSS 8.1v15.0v42.32019-02-07
CVE-2019-7578 [HIGH] CWE-125 CVE-2019-7578: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
nvd
CVE-2019-7636P3HIGHCVSS 8.1v15.0v42.32019-02-08
CVE-2019-7636 [HIGH] CWE-125 CVE-2019-7636: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
nvd
CVE-2019-20388P3HIGHCVSS 7.5v15.12020-01-21
CVE-2019-20388 [HIGH] CWE-401 CVE-2019-20388: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
nvd
CVE-2018-14468P3HIGHCVSS 7.5v15.0v15.12019-10-03
CVE-2018-14468 [HIGH] CWE-125 CVE-2018-14468: The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
nvd
CVE-2016-6352P3HIGHCVSS 7.5v42.12016-10-03
CVE-2016-6352 [HIGH] CWE-787 CVE-2016-6352: The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a de The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
nvd
CVE-2018-20546P3HIGHCVSS 8.1v15.02018-12-28
CVE-2018-20546 [HIGH] CWE-190 CVE-2018-20546: There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99. There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
nvd
CVE-2019-7397P3HIGHCVSS 7.5v15.02019-02-05
CVE-2019-7397 [HIGH] CWE-401 CVE-2019-7397: In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in Writ In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
nvd
CVE-2019-16319P3HIGHCVSS 7.5v15.12019-09-15
CVE-2019-16319 [HIGH] CWE-835 CVE-2019-16319: In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loo In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.
nvd
Opensuse Leap vulnerabilities | cvebase