Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 55 of 95
CVE-2019-9778P4HIGHCVSS 7.5v15.12019-03-14
CVE-2019-9778 [HIGH] CWE-125 CVE-2019-9778: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.
nvd
CVE-2015-3138P4HIGHCVSS 7.5v42.22017-09-28
CVE-2015-3138 [HIGH] CWE-20 CVE-2015-3138: print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentatio
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
nvd
CVE-2018-1000880P4MEDIUMCVSS 6.5v15.02018-12-20
CVE-2018-1000880 [MEDIUM] CWE-119 CVE-2018-1000880: libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards)
libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploit
nvd
CVE-2016-1700P4HIGHCVSS 7.5v42.12016-06-05
CVE-2016-1700 [HIGH] CVE-2016-1700: extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not conside
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to extensions.
nvd
CVE-2016-0502P4MEDIUMCVSS 6.5v42.12016-01-21
CVE-2016-0502 [MEDIUM] CVE-2016-0502: Unspecified vulnerability in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote au
Unspecified vulnerability in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2020-14401P4MEDIUMCVSS 6.5v15.1v15.22020-06-17
CVE-2020-14401 [MEDIUM] CWE-190 CVE-2020-14401: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value intege
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
nvd
CVE-2020-14562P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14562 [MEDIUM] CVE-2020-14562: Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that
Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2020-8648P4HIGHCVSS 7.1v15.12020-02-06
CVE-2020-8648 [HIGH] CWE-416 CVE-2020-8648: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_c
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
nvd
CVE-2020-11099P4MEDIUMCVSS 6.5v15.12020-06-22
CVE-2020-11099 [MEDIUM] CWE-125 CVE-2020-11099: In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_licen
In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.
nvd
CVE-2020-11039P4MEDIUMCVSS 6.8v15.12020-05-29
CVE-2020-11039 [MEDIUM] CWE-190 CVE-2020-11039: In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled
In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks. This has been patched in 2.1.0.
nvd
CVE-2018-1129P4MEDIUMCVSS 6.5v15.02018-07-10
CVE-2018-1129 [MEDIUM] CWE-284 CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol. An a
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
nvd
CVE-2016-2150P4HIGHCVSS 7.1v42.12016-06-09
CVE-2016-2150 [HIGH] CVE-2016-2150: SPICE allows local guest OS users to read from or write to arbitrary host memory locations via craft
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
nvd
CVE-2020-11017P4MEDIUMCVSS 6.5v15.12020-05-29
CVE-2020-11017 [MEDIUM] CWE-415 CVE-2020-11017: In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.
nvd
CVE-2020-4033P4MEDIUMCVSS 6.5v15.12020-06-22
CVE-2020-4033 [MEDIUM] CWE-125 CVE-2020-4033: In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
nvd
CVE-2019-11811P4HIGHCVSS 7.0v15.12019-05-07
CVE-2019-11811 [HIGH] CWE-416 CVE-2019-11811: An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted r
An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/char/ipmi/ipmi_si_mem_io.c, and drivers/char/ipmi/ipmi_si_port_io.c.
nvd
CVE-2020-14364P4MEDIUMCVSS 5.0v15.22020-08-31
CVE-2020-14364 [MEDIUM] CWE-125 CVE-2020-14364: An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of se
nvd
CVE-2019-19921P4HIGHCVSS 7.0v15.12020-02-12
CVE-2019-19921 [HIGH] CWE-706 CVE-2019-19921: runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that hap
nvd
CVE-2020-11098P4MEDIUMCVSS 6.5v15.12020-06-22
CVE-2020-11098 [MEDIUM] CWE-125 CVE-2020-11098: In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all
In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.
nvd
CVE-2019-5835P4MEDIUMCVSS 6.5v15.0v15.1+1 more2019-06-27
CVE-2019-5835 [MEDIUM] CWE-125 CVE-2019-5835: Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attack
Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2019-10206P4MEDIUMCVSS 6.5v15.12019-11-22
CVE-2019-10206 [MEDIUM] CWE-522 CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
nvd