cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 52 of 95
CVE-2016-2047P4MEDIUMCVSS 5.9v42.12016-01-27
CVE-2016-2047 [MEDIUM] CWE-254 CVE-2016-2047: The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 1 The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName
nvd
CVE-2020-11521P3MEDIUMCVSS 6.6v15.12020-05-15
CVE-2020-11521 [MEDIUM] CWE-125 CVE-2020-11521: libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
nvd
CVE-2019-18683P3HIGHCVSS 7.0v15.12019-11-04
CVE-2019-18683 [HIGH] CWE-362 CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exp An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem
nvd
CVE-2018-10913P4MEDIUMCVSS 6.5v15.12018-09-04
CVE-2018-10913 [MEDIUM] CWE-209 CVE-2018-10913: An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
nvd
CVE-2020-12803P4MEDIUMCVSS 6.5v15.12020-06-08
CVE-2020-12803 [MEDIUM] CWE-20 CVE-2020-12803: ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained f ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.
nvd
CVE-2020-10753P4MEDIUMCVSS 6.5v15.12020-06-26
CVE-2020-10753 [MEDIUM] CWE-113 CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is rel A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are v
nvd
CVE-2020-15707P4MEDIUMCVSS 6.4v15.1v15.22020-07-29
CVE-2020-15707 [MEDIUM] CWE-362 CVE-2020-15707: Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efili Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command
nvd
CVE-2020-1945P4MEDIUMCVSS 6.3v15.22020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2016-4955P4MEDIUMCVSS 5.9v42.12016-07-05
CVE-2016-4955 [MEDIUM] CWE-362 CVE-2016-4955: ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial o ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.
nvd
CVE-2019-20011P4HIGHCVSS 8.8v15.12019-12-27
CVE-2019-20011 [HIGH] CWE-125 CVE-2019-20011: An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
nvd
CVE-2016-2831P4HIGHCVSS 8.8v42.12016-06-13
CVE-2016-2831 [HIGH] CWE-254 CVE-2016-2831: Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves th Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
nvd
CVE-2016-5150P4HIGHCVSS 8.8v42.12016-09-11
CVE-2016-5150 [HIGH] CWE-416 CVE-2016-5150: WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) o
nvd
CVE-2016-1695P4HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1695 [HIGH] CVE-2016-1695: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1703P4HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1703 [HIGH] CVE-2016-1703: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-7445P4HIGHCVSS 7.5v42.12016-10-03
CVE-2016-7445 [HIGH] CWE-476 CVE-2016-7445: convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointe convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
nvd
CVE-2016-7448P3HIGHCVSS 7.5v42.12017-02-06
CVE-2016-7448 [HIGH] CWE-399 CVE-2016-7448: The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of ser The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.
nvd
CVE-2019-7398P4HIGHCVSS 7.5v15.02019-02-05
CVE-2019-7398 [HIGH] CWE-401 CVE-2019-7398: In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c. In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
nvd
CVE-2019-19049P4HIGHCVSS 7.5v15.12019-11-18
CVE-2019-19049 [HIGH] CWE-401 CVE-2019-19049: A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel befor A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot
nvd
CVE-2019-14870P3MEDIUMCVSS 5.4v15.12019-12-10
CVE-2019-14870 [MEDIUM] CWE-285 CVE-2019-14870: All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients t
nvd
CVE-2016-7449P4HIGHCVSS 7.5v42.12017-02-06
CVE-2016-7449 [HIGH] CWE-125 CVE-2016-7449: The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string.
nvd
Opensuse Leap vulnerabilities | cvebase