cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 42 of 95
CVE-2016-1897P3MEDIUMCVSS 5.5v42.12016-01-15
CVE-2016-1897 [MEDIUM] CWE-200 CVE-2016-1897: FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
nvd
CVE-2020-7044P3HIGHCVSS 7.5v15.12020-01-16
CVE-2020-7044 [HIGH] CWE-125 CVE-2020-7044: In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissect In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
nvd
CVE-2016-9959P3HIGHCVSS 7.8v42.22017-04-12
CVE-2016-9959 [HIGH] CWE-125 CVE-2016-9959: game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
nvd
CVE-2019-9770P3HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9770 [HIGH] CWE-787 CVE-2019-9770: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in t An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension.
nvd
CVE-2019-9773P3HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9773 [HIGH] CWE-787 CVE-2019-9773: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in t An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.
nvd
CVE-2020-6095P3HIGHCVSS 7.5v15.12020-03-27
CVE-2020-6095 [HIGH] CWE-690 CVE-2020-6095: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/ An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2019-13307P3HIGHCVSS 7.8v15.0v15.12019-07-05
CVE-2019-13307 [HIGH] CWE-787 CVE-2019-13307: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImage ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
nvd
CVE-2019-1551P3MEDIUMCVSS 5.3v15.12019-12-06
CVE-2019-1551 [MEDIUM] CWE-190 CVE-2019-1551: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512 There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are conside
nvd
CVE-2019-14492P3HIGHCVSS 7.5v15.12019-08-01
CVE-2019-14492 [HIGH] CWE-125 CVE-2019-14492: An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/ An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
nvd
CVE-2020-14398P3HIGHCVSS 7.5v15.22020-06-17
CVE-2020-14398 [HIGH] CWE-835 CVE-2020-14398: An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
nvd
CVE-2019-20840P3HIGHCVSS 7.5v15.22020-06-17
CVE-2019-20840 [HIGH] CWE-787 CVE-2019-20840: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.
nvd
CVE-2019-9894P3HIGHCVSS 7.5v15.02019-03-21
CVE-2019-9894 [HIGH] CWE-320 CVE-2019-9894: A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before ho A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
nvd
CVE-2019-19918P3HIGHCVSS 7.8v15.1v15.22019-12-20
CVE-2019-19918 [HIGH] CWE-787 CVE-2019-19918: Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
nvd
CVE-2019-17185P3HIGHCVSS 7.5v15.12020-03-21
CVE-2019-17185 [HIGH] CWE-662 CVE-2019-17185: In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handl In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack.
nvd
CVE-2020-9272P3HIGHCVSS 7.5v15.12020-02-20
CVE-2020-9272 [HIGH] CWE-125 CVE-2020-9272: ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_tex ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
nvd
CVE-2020-11865P3HIGHCVSS 7.8v15.12020-05-11
CVE-2020-11865 [HIGH] CWE-119 CVE-2020-11865: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access. libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
nvd
CVE-2020-1269P3HIGHCVSS 7.8v15.1v15.22020-06-09
CVE-2020-1269 [HIGH] CVE-2020-1269: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-130
nvd
CVE-2019-14816P3HIGHCVSS 7.8v15.0v15.12019-09-20
CVE-2019-14816 [HIGH] CWE-122 CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wif There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2019-14814P3HIGHCVSS 7.8v15.0v15.12019-09-20
CVE-2019-14814 [HIGH] CWE-122 CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marve There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2019-8912P3HIGHCVSS 7.8v15.02019-02-18
CVE-2019-8912 [HIGH] CWE-416 CVE-2019-8912: In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL valu In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.
nvd
Opensuse Leap vulnerabilities | cvebase