cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 51 of 95
CVE-2018-10380P4HIGHCVSS 7.8v15.0v42.32018-05-08
CVE-2018-10380 [HIGH] CWE-59 CVE-2018-10380: kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files v kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
nvd
CVE-2020-24977P4MEDIUMCVSS 6.5v15.1v15.22020-09-04
CVE-2020-24977 [MEDIUM] CWE-125 CVE-2020-24977: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesIntern GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
nvd
CVE-2020-0561P4HIGHCVSS 7.8v15.12020-02-13
CVE-2020-0561 [HIGH] CWE-665 CVE-2020-0561: Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-5819P4HIGHCVSS 7.8v15.0v15.1+1 more2019-06-27
CVE-2019-5819 [HIGH] CWE-20 CVE-2019-5819: Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allo Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
nvd
CVE-2016-10937P4HIGHCVSS 7.5v15.12019-09-08
CVE-2016-10937 [HIGH] CWE-295 CVE-2016-10937: IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
nvd
CVE-2017-13077P4MEDIUMCVSS 6.8v42.2v42.32017-10-17
CVE-2017-13077 [MEDIUM] CWE-330 CVE-2017-13077: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temp Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2016-1938P4MEDIUMCVSS 6.5v42.12016-01-31
CVE-2016-1938 [MEDIUM] CWE-310 CVE-2016-1938: The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21 The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.
nvd
CVE-2020-2907P4HIGHCVSS 7.5v15.12020-04-15
CVE-2020-2907 [HIGH] CWE-20 CVE-2020-2907: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualB
nvd
CVE-2020-14649P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14649 [HIGH] CVE-2020-14649: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
nvd
CVE-2020-14646P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14646 [HIGH] CVE-2020-14646: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
nvd
CVE-2020-14699P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14699 [HIGH] CWE-191 CVE-2020-14699: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virt
nvd
CVE-2020-14676P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14676 [HIGH] CWE-125 CVE-2020-14676: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virt
nvd
CVE-2020-14647P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14647 [HIGH] CVE-2020-14647: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
nvd
CVE-2017-13084P4MEDIUMCVSS 6.8v42.2v42.32017-10-17
CVE-2017-13084 [MEDIUM] CWE-323 CVE-2017-13084: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Tr Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2020-14674P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14674 [HIGH] CWE-367 CVE-2020-14674: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virt
nvd
CVE-2020-14675P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14675 [HIGH] CWE-367 CVE-2020-14675: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virt
nvd
CVE-2020-14677P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14677 [HIGH] CWE-367 CVE-2020-14677: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virt
nvd
CVE-2020-14713P4HIGHCVSS 7.5v15.1v15.22020-07-15
CVE-2020-14713 [HIGH] CVE-2020-14713: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
nvd
CVE-2017-13086P4MEDIUMCVSS 6.8v42.2v42.32017-10-17
CVE-2017-13086 [MEDIUM] CWE-323 CVE-2017-13086: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2019-9325P3MEDIUMCVSS 6.5v15.12019-09-27
CVE-2019-9325 [MEDIUM] CWE-125 CVE-2019-9325: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302
nvd
Opensuse Leap vulnerabilities | cvebase