cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 62 of 95
CVE-2019-19046P4MEDIUMCVSS 6.5v15.12019-11-18
CVE-2019-19046 [MEDIUM] CWE-401 CVE-2019-19046: A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Li A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: third parties dispute the relevance of this because an attacker cannot realistically contr
nvd
CVE-2015-7499P4MEDIUMCVSS 5.0v42.12015-12-15
CVE-2015-7499 [MEDIUM] CWE-119 CVE-2015-7499: Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows contex Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
nvd
CVE-2019-14981P4MEDIUMCVSS 6.5v15.0v15.12019-08-12
CVE-2019-14981 [MEDIUM] CWE-369 CVE-2019-14981: In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.
nvd
CVE-2020-24553P4MEDIUMCVSS 6.1v15.1v15.22020-09-02
CVE-2020-24553 [MEDIUM] CWE-79 CVE-2020-24553: Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI h Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
nvd
CVE-2020-11019P4MEDIUMCVSS 6.5v15.12020-05-29
CVE-2020-11019 [MEDIUM] CWE-125 CVE-2020-11019: In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible cra In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0.
nvd
CVE-2018-16846P4MEDIUMCVSS 6.5v15.02019-01-15
CVE-2018-16846 [MEDIUM] CWE-770 CVE-2018-16846: It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
nvd
CVE-2019-14980P4MEDIUMCVSS 6.5v15.0v15.12019-08-12
CVE-2019-14980 [MEDIUM] CWE-416 CVE-2019-14980: In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.
nvd
CVE-2020-24394P4HIGHCVSS 7.1v15.12020-08-19
CVE-2020-24394 [HIGH] CWE-732 CVE-2020-24394: In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.
nvd
CVE-2019-13626P4MEDIUMCVSS 6.5v15.0v15.12019-07-17
CVE-2019-13626 [MEDIUM] CWE-125 CVE-2019-13626: SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
nvd
CVE-2019-11486P4HIGHCVSS 7.0v15.1v42.32019-04-23
CVE-2019-11486 [HIGH] CWE-362 CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 h The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.
nvd
CVE-2019-5818P4MEDIUMCVSS 6.5v15.0v15.1+1 more2019-06-27
CVE-2019-5818 [MEDIUM] CWE-908 CVE-2019-5818: Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obt Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
nvd
CVE-2020-6564P4MEDIUMCVSS 6.5v15.1v15.22020-09-21
CVE-2020-6564 [MEDIUM] CWE-281 CVE-2020-6564: Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
nvd
CVE-2019-5837P4MEDIUMCVSS 6.5v15.0v15.1+1 more2019-06-27
CVE-2019-5837 [MEDIUM] CVE-2019-5837: Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote a Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6568P4MEDIUMCVSS 6.5v15.1v15.22020-09-21
CVE-2020-6568 [MEDIUM] CVE-2020-6568: Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6562P4MEDIUMCVSS 6.5v15.1v15.22020-09-21
CVE-2020-6562 [MEDIUM] CWE-79 CVE-2020-6562: Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote att Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6565P4MEDIUMCVSS 6.5v15.1v15.22020-09-21
CVE-2020-6565 [MEDIUM] CVE-2020-6565: Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remo Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-6494P4MEDIUMCVSS 6.5v15.12020-06-03
CVE-2020-6494 [MEDIUM] CVE-2020-6494: Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2016-1687P4MEDIUMCVSS 6.5v42.12016-06-05
CVE-2016-1687 [MEDIUM] CWE-200 CVE-2016-1687: The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public e The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.
nvd
CVE-2019-5844P4MEDIUMCVSS 6.5v15.12020-01-03
CVE-2019-5844 [MEDIUM] CWE-787 CVE-2019-5844: Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5846P4MEDIUMCVSS 6.5v15.12020-01-03
CVE-2019-5846 [MEDIUM] CWE-787 CVE-2019-5846: Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Opensuse Leap vulnerabilities | cvebase