Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 54 of 95
CVE-2020-2958P4HIGHCVSS 7.5v15.12020-04-15
CVE-2020-2958 [HIGH] CVE-2020-2958: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whi
nvd
CVE-2020-1700P4MEDIUMCVSS 6.5v15.12020-02-07
CVE-2020-1700 [MEDIUM] CWE-400 CVE-2020-1700: A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenti
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT sockets, eventually leading to the
nvd
CVE-2019-16782P4MEDIUMCVSS 5.9v15.12019-12-18
CVE-2019-16782 [MEDIUM] CWE-208 CVE-2019-16782: There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vuln
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding
nvd
CVE-2020-7070P3MEDIUMCVSS 5.3v15.1v15.22020-10-02
CVE-2020-7070 [MEDIUM] CWE-20 CVE-2020-7070: In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processin
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. S
nvd
CVE-2020-4030P4MEDIUMCVSS 6.5v15.12020-06-22
CVE-2020-4030 [MEDIUM] CWE-125 CVE-2020-4030: In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass s
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
nvd
CVE-2016-2825P4MEDIUMCVSS 6.5v42.12016-06-13
CVE-2016-2825 [MEDIUM] CWE-284 CVE-2016-2825: Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
nvd
CVE-2016-5161P4HIGHCVSS 8.8v42.12016-09-11
CVE-2016-5161 [HIGH] CWE-704 CVE-2016-5161: The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as us
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site that le
nvd
CVE-2020-8130P4MEDIUMCVSS 6.4v15.12020-02-24
CVE-2020-8130 [MEDIUM] CWE-78 CVE-2020-8130: There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplyin
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
nvd
CVE-2016-1704P4HIGHCVSS 8.8v42.12016-07-03
CVE-2016-1704 [HIGH] CVE-2016-1704: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1701P4HIGHCVSS 8.8v42.12016-06-05
CVE-2016-1701 [HIGH] CVE-2016-1701: The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
nvd
CVE-2018-18506P4MEDIUMCVSS 5.9v15.0v42.32019-02-05
CVE-2018-18506 [MEDIUM] CVE-2018-18506: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file o
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attack
nvd
CVE-2019-19060P4HIGHCVSS 7.5v15.12019-11-18
CVE-2019-19060 [HIGH] CWE-401 CVE-2019-19060: A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.
nvd
CVE-2013-4118P4HIGHCVSS 7.5v42.12016-10-03
CVE-2013-4118 [HIGH] CWE-476 CVE-2013-4118: FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer derefe
FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
nvd
CVE-2016-5104P4MEDIUMCVSS 5.3v42.12016-06-13
CVE-2016-5104 [MEDIUM] CWE-284 CVE-2016-5104: The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attac
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
nvd
CVE-2019-11041P4HIGHCVSS 7.1v15.02019-08-09
CVE-2019-11041 [HIGH] CWE-125 CVE-2019-11041: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2019-11042P4HIGHCVSS 7.1v15.02019-08-09
CVE-2019-11042 [HIGH] CWE-125 CVE-2019-11042: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2018-14879P4HIGHCVSS 7.0v15.0v15.12019-10-03
CVE-2018-14879 [HIGH] CWE-120 CVE-2018-14879: The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
nvd
CVE-2020-10135P3MEDIUMCVSS 5.4v15.12020-05-19
CVE-2020-10135 [MEDIUM] CWE-757 CVE-2020-10135: Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired r
nvd
CVE-2016-10064P4HIGHCVSS 7.8v42.12017-03-02
CVE-2016-10064 [HIGH] CWE-119 CVE-2016-10064: Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a de
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
nvd
CVE-2019-9777P4HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9777 [HIGH] CWE-125 CVE-2019-9777: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec.
nvd