cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 45 of 95
CVE-2020-10592P3HIGHCVSS 7.5v15.12020-03-23
CVE-2020-10592 [HIGH] CVE-2020-10592: Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
nvd
CVE-2019-9897P3HIGHCVSS 7.5v15.02019-03-21
CVE-2019-9897 [HIGH] CVE-2019-9897: Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY v Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
nvd
CVE-2020-13962P3HIGHCVSS 7.5v15.22020-06-09
CVE-2020-13962 [HIGH] CVE-2020-13962: Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandle Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
nvd
CVE-2019-7175P3HIGHCVSS 7.5v15.02019-03-07
CVE-2019-7175 [HIGH] CWE-401 CVE-2019-7175: In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c. In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.
nvd
CVE-2019-9779P3HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9779 [HIGH] CVE-2019-9779: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776).
nvd
CVE-2016-3100P3HIGHCVSS 8.4v42.12016-07-13
CVE-2016-3100 [HIGH] CWE-200 CVE-2016-3100: kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allow kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.
nvd
CVE-2020-2742P3HIGHCVSS 8.2v15.12020-04-15
CVE-2020-2742 [HIGH] CWE-190 CVE-2020-2742: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBo
nvd
CVE-2018-21247P3HIGHCVSS 7.5v15.22020-06-17
CVE-2018-21247 [HIGH] CWE-909 CVE-2018-21247: An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialize An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.
nvd
CVE-2020-6510P3HIGHCVSS 7.8v15.1v15.22020-07-22
CVE-2020-6510 [HIGH] CWE-787 CVE-2020-6510: Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote att Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-7213P3MEDIUMCVSS 6.8v42.12015-12-16
CVE-2015-7213 [MEDIUM] CWE-189 CVE-2015-7213: Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefrigh Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.
nvd
CVE-2020-14628P3HIGHCVSS 8.2v15.1v15.22020-07-15
CVE-2020-14628 [HIGH] CVE-2020-14628: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Wh
nvd
CVE-2020-13114P3HIGHCVSS 7.5v15.12020-05-21
CVE-2020-13114 [HIGH] CWE-770 CVE-2020-13114: An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerN An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
nvd
CVE-2018-10916P3MEDIUMCVSS 6.5v42.32018-08-01
CVE-2018-10916 [MEDIUM] CWE-20 CVE-2018-10916: It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current worki
nvd
CVE-2020-11653P3HIGHCVSS 7.5v15.12020-04-08
CVE-2020-11653 [HIGH] CWE-617 CVE-2020-11653: An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x b An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
nvd
CVE-2020-11866P3HIGHCVSS 7.8v15.12020-05-11
CVE-2020-11866 [HIGH] CWE-416 CVE-2020-11866: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free. libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
nvd
CVE-2016-1898P3MEDIUMCVSS 5.5v42.12016-01-15
CVE-2016-1898 [MEDIUM] CWE-200 CVE-2016-1898: FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
nvd
CVE-2019-17068P3HIGHCVSS 7.5v15.0v15.12019-10-01
CVE-2019-17068 [HIGH] CWE-74 CVE-2019-17068: PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a sess PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
nvd
CVE-2016-6318P3HIGHCVSS 7.8v42.12016-09-07
CVE-2016-6318 [HIGH] CWE-787 CVE-2016-6318: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows loc Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
nvd
CVE-2019-2740P3MEDIUMCVSS 6.5v15.12019-07-23
CVE-2019-2740 [MEDIUM] CVE-2019-2740: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2018-6954P3HIGHCVSS 7.8v42.32018-02-13
CVE-2018-6954 [HIGH] CWE-59 CVE-2018-6954: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turne
nvd
Opensuse Leap vulnerabilities | cvebase