Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 50 of 95
CVE-2016-1680P3HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1680 [HIGH] CWE-119 CVE-2016-1680: Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome befo
Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2020-8492P4MEDIUMCVSS 6.5v15.12020-01-30
CVE-2020-8492 [MEDIUM] CWE-400 CVE-2020-8492: Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
nvd
CVE-2019-11009P4HIGHCVSS 8.1v15.0v42.32019-04-08
CVE-2019-11009 [HIGH] CWE-125 CVE-2019-11009: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function R
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
nvd
CVE-2014-9848P4HIGHCVSS 7.5v42.22017-03-20
CVE-2014-9848 [HIGH] CWE-399 CVE-2014-9848: Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption)
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
nvd
CVE-2019-16995P4HIGHCVSS 7.5v15.0v15.12019-09-30
CVE-2019-16995 [HIGH] CWE-401 CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
nvd
CVE-2015-7205P4CRITICALCVSS 10.0v42.12015-12-16
CVE-2015-7205 [CRITICAL] CWE-189 CVE-2015-7205: Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 an
Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a crafted WebRTC RTP packet.
nvd
CVE-2019-11007P3HIGHCVSS 8.1v15.0v42.32019-04-08
CVE-2019-11007 [HIGH] CWE-125 CVE-2019-11007: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGIma
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
nvd
CVE-2016-8689P4HIGHCVSS 7.5v42.22017-02-15
CVE-2016-8689 [HIGH] CWE-125 CVE-2016-8689: The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote att
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archive.
nvd
CVE-2019-12979P4HIGHCVSS 7.8v15.0v15.12019-06-26
CVE-2019-12979 [HIGH] CWE-665 CVE-2019-12979: ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings funct
ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.
nvd
CVE-2016-4414P3HIGHCVSS 7.5v42.12016-06-13
CVE-2016-4414 [HIGH] CVE-2016-4414: The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attacker
The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.
nvd
CVE-2016-5706P4HIGHCVSS 7.5v42.12016-07-03
CVE-2016-5706 [HIGH] CWE-399 CVE-2016-5706: js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before
js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts parameter.
nvd
CVE-2016-1651P3HIGHCVSS 8.1v42.12016-04-18
CVE-2016-1651 [HIGH] CWE-200 CVE-2016-1651: fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted JPEG 2000 data in a PDF document.
nvd
CVE-2019-9771P3HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9771 [HIGH] CWE-476 CVE-2019-9771: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.
nvd
CVE-2019-9776P4HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9776 [HIGH] CWE-476 CVE-2019-9776: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779).
nvd
CVE-2019-9772P3HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9772 [HIGH] CWE-476 CVE-2019-9772: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.
nvd
CVE-2016-10050P4HIGHCVSS 7.8v42.1v42.22017-03-23
CVE-2016-10050 [HIGH] CWE-119 CVE-2016-10050: Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allow
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
nvd
CVE-2019-17178P4HIGHCVSS 7.5v15.0v15.12019-10-04
CVE-2019-17178 [HIGH] CWE-252 CVE-2019-17178: HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in Free
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
nvd
CVE-2020-2905P4HIGHCVSS 8.2v15.12020-04-15
CVE-2020-2905 [HIGH] CVE-2020-2905: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While
nvd
CVE-2016-5301P4HIGHCVSS 7.5v42.12016-06-30
CVE-2016-5301 [HIGH] CWE-20 CVE-2016-5301: The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial
The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP response or possibly a (2) UPnP broadcast.
nvd
CVE-2020-9429P4HIGHCVSS 7.5v15.12020-02-27
CVE-2020-9429 [HIGH] CWE-476 CVE-2020-9429: In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissect
In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.
nvd