Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 66 of 95
CVE-2016-10165P4HIGHCVSS 7.1v42.12017-02-03
CVE-2016-10165 [HIGH] CWE-125 CVE-2016-10165: The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
nvd
CVE-2020-10761P4MEDIUMCVSS 5.0v15.22020-06-09
CVE-2020-10761 [MEDIUM] CWE-617 CVE-2020-10761: An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions be
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
nvd
CVE-2015-5309P4MEDIUMCVSS 4.3v42.12015-12-07
CVE-2015-5309 [MEDIUM] CWE-189 CVE-2015-5309: Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a de
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which triggers a buffer underflow.
nvd
CVE-2016-9436P4MEDIUMCVSS 6.5v42.22017-01-20
CVE-2016-9436 [MEDIUM] CWE-20 CVE-2016-9436: parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote
parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a tag.
nvd
CVE-2016-6132P4MEDIUMCVSS 6.5v42.12016-08-12
CVE-2016-6132 [MEDIUM] CWE-125 CVE-2016-6132: The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remo
The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
nvd
CVE-2016-6214P4MEDIUMCVSS 6.5v42.12016-08-12
CVE-2016-6214 [MEDIUM] CWE-125 CVE-2016-6214: gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a deni
gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
nvd
CVE-2018-20467P4MEDIUMCVSS 6.5v15.02018-12-26
CVE-2018-20467 [MEDIUM] CWE-835 CVE-2018-20467: In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and han
In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
nvd
CVE-2018-14498P4MEDIUMCVSS 6.5v15.02019-03-07
CVE-2018-14498 [MEDIUM] CWE-125 CVE-2018-14498: get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers t
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
nvd
CVE-2020-17498P4MEDIUMCVSS 6.5v15.1v15.22020-08-13
CVE-2020-17498 [MEDIUM] CWE-415 CVE-2020-17498: In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/di
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
nvd
CVE-2016-1956P4MEDIUMCVSS 6.5v42.12016-03-13
CVE-2016-1956 [MEDIUM] CWE-399 CVE-2016-1956: Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
nvd
CVE-2020-1983P4MEDIUMCVSS 6.5v15.12020-04-22
CVE-2020-1983 [MEDIUM] CWE-416 CVE-2020-1983: A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allo
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
nvd
CVE-2018-10733P4MEDIUMCVSS 6.5v15.02018-05-04
CVE-2018-10733 [MEDIUM] CWE-125 CVE-2018-10733: There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
nvd
CVE-2018-19869P4MEDIUMCVSS 6.5v15.02018-12-26
CVE-2018-19869 [MEDIUM] CWE-20 CVE-2018-19869: An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qs
An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.
nvd
CVE-2020-3862P4MEDIUMCVSS 6.5v15.12020-02-27
CVE-2020-3862 [MEDIUM] CVE-2020-3862: A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13
A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. A malicious website may be able to cause a denial of service.
nvd
CVE-2018-19539P4MEDIUMCVSS 6.5v15.02018-11-26
CVE-2018-19539 [MEDIUM] CWE-617 CVE-2018-19539: An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_rea
An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.
nvd
CVE-2018-19871P4MEDIUMCVSS 6.5v15.02018-12-26
CVE-2018-19871 [MEDIUM] CWE-400 CVE-2018-19871: An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.
An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.
nvd
CVE-2019-18390P4HIGHCVSS 7.1v15.12019-12-23
CVE-2019-18390 [HIGH] CWE-125 CVE-2019-18390: An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer t
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
nvd
CVE-2015-8864P4MEDIUMCVSS 6.1v42.12017-04-13
CVE-2015-8864 [MEDIUM] CWE-79 CVE-2015-8864: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 al
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
nvd
CVE-2019-11721P4MEDIUMCVSS 6.5v15.0v15.12019-07-23
CVE-2019-11721 [MEDIUM] CVE-2019-11721: The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. T
The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.
nvd
CVE-2019-20013P4MEDIUMCVSS 6.5v15.12019-12-27
CVE-2019-20013 [MEDIUM] CWE-770 CVE-2019-20013: An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessi
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
nvd