Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 47 of 95
CVE-2016-6261P3HIGHCVSS 7.5v42.12016-09-07
CVE-2016-6261 [HIGH] CWE-125 CVE-2016-6261: The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers
The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
nvd
CVE-2016-9399P3HIGHCVSS 7.5v15.1v15.22017-03-23
CVE-2016-9399 [HIGH] CWE-617 CVE-2016-9399: The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
nvd
CVE-2018-16228P3HIGHCVSS 7.5v15.0v15.12019-10-03
CVE-2018-16228 [HIGH] CWE-125 CVE-2018-16228: The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().
The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().
nvd
CVE-2017-9814P3HIGHCVSS 7.5v15.12017-07-17
CVE-2017-9814 [HIGH] CWE-125 CVE-2017-9814: cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of ser
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
nvd
CVE-2015-8076P3HIGHCVSS 7.5v42.12015-12-03
CVE-2015-8076 [HIGH] CWE-119 CVE-2015-8076: The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
nvd
CVE-2020-6614P3HIGHCVSS 8.1v15.12020-01-08
CVE-2020-6614 [HIGH] CWE-125 CVE-2020-6614: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
nvd
CVE-2020-6612P3HIGHCVSS 8.1v15.12020-01-08
CVE-2020-6612 [HIGH] CWE-125 CVE-2020-6612: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
nvd
CVE-2020-6613P3HIGHCVSS 8.1v15.12020-01-08
CVE-2020-6613 [HIGH] CWE-125 CVE-2020-6613: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
nvd
CVE-2015-6031P3MEDIUMCVSS 6.8v42.12015-11-02
CVE-2015-6031 [MEDIUM] CWE-119 CVE-2015-6031: Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnP
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
nvd
CVE-2019-9923P3HIGHCVSS 7.5v15.02019-03-22
CVE-2019-9923 [HIGH] CWE-476 CVE-2019-9923: pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing cer
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
nvd
CVE-2016-1254P3HIGHCVSS 7.5v42.22017-12-05
CVE-2016-1254 [HIGH] CWE-119 CVE-2016-1254: Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a c
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
nvd
CVE-2017-5333P3HIGHCVSS 7.8v42.1v42.22019-11-04
CVE-2017-5333 [HIGH] CWE-190 CVE-2017-5333: Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icout
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
nvd
CVE-2016-0747P3MEDIUMCVSS 5.3v42.12016-02-15
CVE-2016-0747 [MEDIUM] CWE-400 CVE-2016-0747: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution,
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
nvd
CVE-2018-18225P3HIGHCVSS 7.5v15.12018-10-12
CVE-2018-18225 [HIGH] CWE-682 CVE-2018-18225: In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/p
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
nvd
CVE-2017-5332P3HIGHCVSS 7.8v42.1v42.22019-11-04
CVE-2017-5332 [HIGH] CWE-119 CVE-2017-5332: The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access un
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
nvd
CVE-2019-13602P3HIGHCVSS 7.8v15.0v15.12019-07-14
CVE-2019-13602 [HIGH] CWE-191 CVE-2019-13602: An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
nvd
CVE-2020-9430P3HIGHCVSS 7.5v15.12020-02-27
CVE-2020-9430 [HIGH] CWE-20 CVE-2020-9430: In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could cr
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.
nvd
CVE-2016-2821P3HIGHCVSS 7.5v42.12016-06-13
CVE-2016-2821 [HIGH] CVE-2016-2821: Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and F
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.
nvd
CVE-2020-9431P3HIGHCVSS 7.5v15.12020-02-27
CVE-2020-9431 [HIGH] CWE-401 CVE-2020-9431: In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak m
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.
nvd
CVE-2019-17177P3HIGHCVSS 7.5v15.0v15.12019-10-04
CVE-2019-17177 [HIGH] CWE-401 CVE-2019-17177: libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks becaus
libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
nvd