cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 53 of 95
CVE-2019-7396P4HIGHCVSS 7.5v15.02019-02-05
CVE-2019-7396 [HIGH] CWE-401 CVE-2019-7396: In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c. In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.
nvd
CVE-2019-7395P4HIGHCVSS 7.5v15.02019-02-05
CVE-2019-7395 [HIGH] CWE-401 CVE-2019-7395: In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c. In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
nvd
CVE-2016-4579P4HIGHCVSS 7.5v42.12016-06-13
CVE-2016-4579 [HIGH] CWE-20 CVE-2016-4579: Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and cr Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
nvd
CVE-2016-2039P4MEDIUMCVSS 5.3v42.12016-02-20
CVE-2016-2039 [MEDIUM] CWE-200 CVE-2016-2039: libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x bef libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
nvd
CVE-2016-4574P4HIGHCVSS 7.5v42.12016-06-13
CVE-2016-4574 [HIGH] CVE-2016-4574: Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
nvd
CVE-2016-10051P4HIGHCVSS 7.8v42.1v42.22017-03-23
CVE-2016-10051 [HIGH] CWE-416 CVE-2016-10051: Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 all Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
nvd
CVE-2015-7222P4MEDIUMCVSS 6.8v42.12015-12-16
CVE-2015-7222 [MEDIUM] CWE-189 CVE-2015-7222: Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Fir Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer
nvd
CVE-2019-17069P4HIGHCVSS 7.5v15.0v15.12019-10-01
CVE-2019-17069 [HIGH] CWE-416 CVE-2019-17069: PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed m PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.
nvd
CVE-2020-13143P4MEDIUMCVSS 6.5v15.1v15.22020-05-18
CVE-2020-13143 [MEDIUM] CWE-125 CVE-2020-13143: gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 r gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
nvd
CVE-2019-12521P4MEDIUMCVSS 5.9v15.12020-04-15
CVE-2019-12521 [MEDIUM] CWE-193 CVE-2019-12521: An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements i An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Hea
nvd
CVE-2016-1942P4HIGHCVSS 7.4v42.12016-01-31
CVE-2016-1942 [HIGH] CWE-20 CVE-2016-1942: Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in t Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
nvd
CVE-2016-1494P4MEDIUMCVSS 5.3v42.12016-01-13
CVE-2016-1494 [MEDIUM] CWE-20 CVE-2016-1494: The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
nvd
CVE-2016-1691P4HIGHCVSS 7.5v42.12016-06-05
CVE-2016-1691 [HIGH] CWE-119 CVE-2016-1691: Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.
nvd
CVE-2017-5331P4HIGHCVSS 7.8v42.1v42.22019-11-04
CVE-2017-5331 [HIGH] CWE-190 CVE-2017-5331: Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 all Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
nvd
CVE-2019-13117P4MEDIUMCVSS 5.3v15.12019-07-01
CVE-2019-13117 [MEDIUM] CWE-908 CVE-2019-13117: In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitiali In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
nvd
CVE-2019-5798P4MEDIUMCVSS 6.5v15.0v15.1+1 more2019-05-23
CVE-2019-5798 [MEDIUM] CWE-125 CVE-2019-5798: Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote atta Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2019-9433P3MEDIUMCVSS 6.5v15.12019-09-27
CVE-2019-9433 [MEDIUM] CWE-20 CVE-2019-9433: In libvpx, there is a possible information disclosure due to improper input validation. This could l In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354
nvd
CVE-2020-2911P4HIGHCVSS 7.5v15.12020-04-15
CVE-2020-2911 [HIGH] CVE-2020-2911: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whi
nvd
CVE-2019-2864P4HIGHCVSS 7.5v15.0v15.12019-07-23
CVE-2019-2864 [HIGH] CVE-2019-2864: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vuln
nvd
CVE-2019-2865P4HIGHCVSS 7.5v15.0v15.12019-07-23
CVE-2019-2865 [HIGH] CVE-2019-2865: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vuln
nvd
Opensuse Leap vulnerabilities | cvebase