Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 65 of 95
CVE-2021-26676P4MEDIUMCVSS 6.5v15.22021-02-09
CVE-2021-26676 [MEDIUM] CVE-2021-26676: gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack inf
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
nvd
CVE-2020-7106P4MEDIUMCVSS 6.1v15.12020-01-16
CVE-2020-7106 [MEDIUM] CWE-79 CVE-2020-7106: Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.ph
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
nvd
CVE-2020-6495P4MEDIUMCVSS 6.5v15.12020-06-03
CVE-2020-6495 [MEDIUM] CWE-276 CVE-2020-6495: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2015-7940P4MEDIUMCVSS 5.0v42.12015-11-09
CVE-2015-7940 [MEDIUM] CWE-200 CVE-2015-7940: The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve,
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
nvd
CVE-2019-5793P4MEDIUMCVSS 6.5v15.0v15.1+1 more2019-05-23
CVE-2019-5793 [MEDIUM] CWE-20 CVE-2019-5793: Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remot
Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page.
nvd
CVE-2020-14309P4MEDIUMCVSS 6.7v15.1v15.22020-07-30
CVE-2020-14309 [MEDIUM] CWE-190 CVE-2020-14309: There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containin
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
nvd
CVE-2020-14344P4MEDIUMCVSS 6.7v15.1v15.22020-08-05
CVE-2020-14344 [MEDIUM] CWE-190 CVE-2020-14344: An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client w
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
nvd
CVE-2019-5814P4MEDIUMCVSS 6.5v15.0v15.1+1 more2019-06-27
CVE-2019-5814 [MEDIUM] CWE-352 CVE-2019-5814: Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-26934P4MEDIUMCVSS 6.1v15.1v15.22020-10-10
CVE-2020-26934 [MEDIUM] CWE-79 CVE-2020-26934: phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a cra
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
nvd
CVE-2020-0431P4MEDIUMCVSS 6.7v15.1v15.22020-09-17
CVE-2020-0431 [MEDIUM] CWE-787 CVE-2020-0431: In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check.
In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459
nvd
CVE-2019-9456P4MEDIUMCVSS 6.7v15.0v15.12019-09-06
CVE-2019-9456 [MEDIUM] CWE-787 CVE-2019-9456: In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing b
In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-10756P4MEDIUMCVSS 6.5v15.0v15.12020-07-09
CVE-2020-10756 [MEDIUM] CWE-125 CVE-2020-10756: An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emu
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This fl
nvd
CVE-2020-13614P4MEDIUMCVSS 5.9v15.12020-05-26
CVE-2020-13614 [MEDIUM] CWE-295 CVE-2020-13614: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verifi
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
nvd
CVE-2020-12105P4MEDIUMCVSS 5.9v15.12020-04-23
CVE-2020-12105 [MEDIUM] CWE-755 CVE-2020-12105: OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which mi
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
nvd
CVE-2019-15165P4MEDIUMCVSS 5.3v15.0v15.12019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvd
CVE-2020-7598P4MEDIUMCVSS 5.6v15.12020-03-11
CVE-2020-7598 [MEDIUM] CWE-1321 CVE-2020-7598: minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
nvd
CVE-2016-6225P4MEDIUMCVSS 5.9v42.1v42.22017-03-23
CVE-2016-6225 [MEDIUM] CVE-2016-6225: xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initiali
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
nvd
CVE-2019-14861P4MEDIUMCVSS 5.3v15.12019-12-10
CVE-2019-14861 [MEDIUM] CWE-276 CVE-2019-14861: All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new rec
nvd
CVE-2017-13080P4MEDIUMCVSS 5.3v42.2v42.32017-10-17
CVE-2017-13080 [MEDIUM] CWE-323 CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during t
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2017-13081P4MEDIUMCVSS 5.3v42.2v42.32017-10-17
CVE-2017-13081 [MEDIUM] CWE-323 CVE-2017-13081: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integr
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
nvd