Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 60 of 95
CVE-2020-6479P4MEDIUMCVSS 6.5v15.12020-05-21
CVE-2020-6479 [MEDIUM] CVE-2020-6479: Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote atta
Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6478P4MEDIUMCVSS 6.5v15.12020-05-21
CVE-2020-6478 [MEDIUM] CVE-2020-6478: Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote
Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6566P4MEDIUMCVSS 6.5v15.1v15.22020-09-21
CVE-2020-6566 [MEDIUM] CVE-2020-6566: Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote att
Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6481P4MEDIUMCVSS 6.5v15.12020-05-21
CVE-2020-6481 [MEDIUM] CVE-2020-6481: Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a r
Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.
nvd
CVE-2020-27672P4HIGHCVSS 7.0v15.1v15.22020-10-22
CVE-2020-27672 [HIGH] CWE-362 CVE-2020-27672: An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
nvd
CVE-2020-15655P4MEDIUMCVSS 6.5v15.22020-08-10
CVE-2020-15655 [MEDIUM] CVE-2020-15655: A redirected HTTP request which is observed or modified through a web extension could bypass existin
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-6567P4MEDIUMCVSS 6.5v15.1v15.22020-09-21
CVE-2020-6567 [MEDIUM] CWE-20 CVE-2020-6567: Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prio
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-5799P4MEDIUMCVSS 6.5v15.0v15.1+1 more2019-05-23
CVE-2019-5799 [MEDIUM] CWE-20 CVE-2019-5799: Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior t
Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2016-5160P4MEDIUMCVSS 6.5v42.12016-09-11
CVE-2016-5160 [MEDIUM] CWE-254 CVE-2016-5160: The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chro
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources field for restrictions on IFRAME elements, which makes it easier for remote attackers to conduct clic
nvd
CVE-2020-6491P4MEDIUMCVSS 6.5v15.12020-05-21
CVE-2020-6491 [MEDIUM] CVE-2020-6491: Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a re
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.
nvd
CVE-2016-5162P4MEDIUMCVSS 6.5v42.12016-09-11
CVE-2016-5162 [MEDIUM] CVE-2016-5162: The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chro
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources field for restrictions on IFRAME elements, which makes it easier for remote attackers to conduct clickjacking
nvd
CVE-2020-6456P4MEDIUMCVSS 6.5v15.12020-04-13
CVE-2020-6456 [MEDIUM] CWE-276 CVE-2020-6456: Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allow
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
nvd
CVE-2015-7575P4MEDIUMCVSS 5.9v42.12016-01-09
CVE-2015-7575 [MEDIUM] CWE-19 CVE-2015-7575: Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
nvd
CVE-2020-6476P4MEDIUMCVSS 6.5v15.12020-05-21
CVE-2020-6476 [MEDIUM] CWE-276 CVE-2020-6476: Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attac
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2020-12415P4MEDIUMCVSS 6.5v15.1v15.22020-07-09
CVE-2020-12415 [MEDIUM] CWE-276 CVE-2020-12415: When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and a
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.
nvd
CVE-2019-18424P4MEDIUMCVSS 6.8v15.02019-10-31
CVE-2019-18424 [MEDIUM] CWE-78 CVE-2019-18424: An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to
nvd
CVE-2020-15705P4MEDIUMCVSS 6.4v15.1v15.22020-07-29
CVE-2020-15705 [MEDIUM] CWE-347 CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions
nvd
CVE-2020-25637P4MEDIUMCVSS 6.7v15.1v15.22020-10-06
CVE-2020-25637 [MEDIUM] CWE-415 CVE-2020-25637: A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsi
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash t
nvd
CVE-2019-20908P4MEDIUMCVSS 6.7v15.12020-07-15
CVE-2019-20908 [MEDIUM] CVE-2019-20908: An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect acce
An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.
nvd
CVE-2020-6444P4MEDIUMCVSS 6.3v15.12020-04-13
CVE-2020-6444 [MEDIUM] CWE-908 CVE-2020-6444: Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to pote
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd