Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 58 of 95
CVE-2019-18932P4HIGHCVSS 7.0v15.12020-01-21
CVE-2019-18932 [HIGH] CWE-59 CVE-2019-18932: log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it (after winning a /tmp/sarg/denied.i
nvd
CVE-2020-6484P4MEDIUMCVSS 6.5v15.12020-05-21
CVE-2020-6484 [MEDIUM] CWE-276 CVE-2020-6484: Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
nvd
CVE-2019-9458P4HIGHCVSS 7.0v15.12019-09-06
CVE-2019-9458 [HIGH] CWE-362 CVE-2019-9458: In the Android kernel in the video driver there is a use after free due to a race condition. This co
In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-11725P4MEDIUMCVSS 6.5v15.0v15.12019-07-23
CVE-2019-11725 [MEDIUM] CVE-2019-11725: When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are display
When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.
nvd
CVE-2019-11046P4MEDIUMCVSS 5.3v15.12019-12-23
CVE-2019-11046 [MEDIUM] CWE-125 CVE-2019-11046: In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of s
nvd
CVE-2020-15706P4MEDIUMCVSS 6.4v15.1v15.22020-07-29
CVE-2020-15706 [MEDIUM] CWE-362 CVE-2020-15706: GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnera
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
nvd
CVE-2019-7317P4MEDIUMCVSS 5.3v15.0v15.1+1 more2019-02-04
CVE-2019-7317 [MEDIUM] CWE-416 CVE-2019-7317: png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_fu
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
nvd
CVE-2016-6207P4MEDIUMCVSS 6.5v42.12016-08-12
CVE-2016-6207 [MEDIUM] CWE-119 CVE-2016-6207: Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.
nvd
CVE-2020-8608P4MEDIUMCVSS 5.6v15.12020-02-06
CVE-2020-8608 [MEDIUM] CWE-120 CVE-2020-8608: In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a bu
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
nvd
CVE-2014-9854P4HIGHCVSS 7.5v42.12017-03-17
CVE-2014-9854 [HIGH] CWE-399 CVE-2014-9854: coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash
coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
nvd
CVE-2019-10214P4MEDIUMCVSS 5.9v15.12019-11-25
CVE-2019-10214 [MEDIUM] CWE-522 CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Ente
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer
nvd
CVE-2019-12449P4MEDIUMCVSS 5.7v15.0v15.12019-05-29
CVE-2019-12449 [MEDIUM] CWE-755 CVE-2019-12449: An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
nvd
CVE-2020-8017P4MEDIUMCVSS 6.3v15.12020-04-02
CVE-2020-8017 [MEDIUM] CWE-367 CVE-2020-8017: A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesyst
A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary fi
nvd
CVE-2019-14833P4MEDIUMCVSS 5.4v15.02019-11-06
CVE-2019-14833 [MEDIUM] CWE-305 CVE-2019-14833: A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, sam
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify p
nvd
CVE-2015-8547P4HIGHCVSS 7.5v42.12016-01-08
CVE-2015-8547 [HIGH] CWE-17 CVE-2015-8547: The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8v15.12020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2018-11212P4MEDIUMCVSS 6.5v15.02018-05-16
CVE-2018-11212 [MEDIUM] CWE-369 CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote a
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
nvd
CVE-2015-8631P4MEDIUMCVSS 6.5v42.12016-02-13
CVE-2015-8631 [MEDIUM] CWE-772 CVE-2015-8631: Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8v15.12020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2016-6172P4MEDIUMCVSS 6.8v42.12016-09-26
CVE-2016-6172 [MEDIUM] CWE-400 CVE-2016-6172: PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a d
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.
nvd