cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 48 of 95
CVE-2019-2867P3HIGHCVSS 8.2v15.0v15.12019-07-23
CVE-2019-2867 [HIGH] CWE-787 CVE-2019-2867: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While th
nvd
CVE-2020-2758P3HIGHCVSS 8.2v15.12020-04-15
CVE-2020-2758 [HIGH] CWE-416 CVE-2020-2758: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBo
nvd
CVE-2020-2908P3HIGHCVSS 8.2v15.12020-04-15
CVE-2020-2908 [HIGH] CWE-20 CVE-2020-2908: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
nvd
CVE-2019-19917P3HIGHCVSS 7.8v15.1v15.22019-12-20
CVE-2019-19917 [HIGH] CWE-120 CVE-2019-19917: Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
nvd
CVE-2020-10593P3HIGHCVSS 7.5v15.12020-03-23
CVE-2020-10593 [HIGH] CWE-401 CVE-2020-10593: Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cau Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit.
nvd
CVE-2016-4478P3HIGHCVSS 7.5v42.12016-06-13
CVE-2016-4478 [HIGH] CWE-119 CVE-2016-4478: Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
nvd
CVE-2019-2866P3HIGHCVSS 8.2v15.0v15.12019-07-23
CVE-2019-2866 [HIGH] CVE-2019-2866: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner
nvd
CVE-2016-1683P3HIGHCVSS 7.5v42.12016-06-05
CVE-2016-1683 [HIGH] CWE-119 CVE-2016-1683: numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespa numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2019-14524P3HIGHCVSS 7.8v15.0v15.12019-08-02
CVE-2019-14524 [HIGH] CVE-2019-14524: An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow vi An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
nvd
CVE-2020-16118P3HIGHCVSS 7.5v15.12020-07-29
CVE-2020-16118 [HIGH] CWE-476 CVE-2020-16118: In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL poi In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.
nvd
CVE-2015-5291P3MEDIUMCVSS 6.8v42.12015-11-02
CVE-2015-5291 [MEDIUM] CWE-119 CVE-2015-5291: Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a
nvd
CVE-2019-13104P3HIGHCVSS 7.8v15.0v15.12019-08-06
CVE-2019-13104 [HIGH] CWE-191 CVE-2019-13104: In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
nvd
CVE-2019-17010P3HIGHCVSS 7.5v15.12020-01-08
CVE-2019-17010 [HIGH] CWE-362 CVE-2019-17010: Under certain conditions, when checking the Resist Fingerprinting preference during device orientati Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-17011P3HIGHCVSS 7.5v15.12020-01-08
CVE-2019-17011 [HIGH] CWE-362 CVE-2019-17011: Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a rac Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-9896P3HIGHCVSS 7.8v15.02019-03-21
CVE-2019-9896 [HIGH] CWE-427 CVE-2019-9896: In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
nvd
CVE-2020-13396P3HIGHCVSS 7.1v15.12020-05-22
CVE-2020-13396 [HIGH] CWE-125 CVE-2020-13396: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
nvd
CVE-2016-5759P3HIGHCVSS 7.8v42.12017-09-08
CVE-2016-5759 [HIGH] CWE-20 CVE-2016-5759: The mkdumprd script called "dracut" in the current working directory "." allows local users to trick The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
nvd
CVE-2020-27671P3HIGHCVSS 7.8v15.1v15.22020-10-22
CVE-2020-27671 [HIGH] CVE-2020-27671: An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a den An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled.
nvd
CVE-2019-17009P3HIGHCVSS 7.8v15.12020-01-08
CVE-2019-17009 [HIGH] CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentiall When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Th
nvd
CVE-2020-27670P3HIGHCVSS 7.8v15.1v15.22020-10-22
CVE-2020-27670 [HIGH] CWE-345 CVE-2020-27670: An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of servi An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated.
nvd
Opensuse Leap vulnerabilities | cvebase