cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 68 of 95
CVE-2020-8228P4MEDIUMCVSS 5.3v15.1v15.22020-10-05
CVE-2020-8228 [MEDIUM] CWE-840 CVE-2020-8228: A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
nvd
CVE-2020-14556P4MEDIUMCVSS 4.8v15.1v15.22020-07-15
CVE-2020-14556 [MEDIUM] CVE-2020-14556: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-14039P4MEDIUMCVSS 5.3v15.1v15.22020-07-17
CVE-2020-14039 [MEDIUM] CWE-295 CVE-2020-14039: In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOpti In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.
nvd
CVE-2020-7041P4MEDIUMCVSS 5.3v15.12020-02-27
CVE-2020-7041 [MEDIUM] CWE-295 CVE-2020-7041: An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c misha An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
nvd
CVE-2017-14804P4MEDIUMCVSS 5.3v42.2v42.32018-03-01
CVE-2017-14804 [MEDIUM] CWE-22 CVE-2017-14804: The build package before 20171128 did not check directory names during extraction of build results t The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
nvd
CVE-2020-2800P4MEDIUMCVSS 4.8v15.1v15.22020-04-15
CVE-2020-2800 [MEDIUM] CVE-2020-2800: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTT Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2020-1765P4MEDIUMCVSS 5.3v15.1v15.22020-01-10
CVE-2020-1765 [MEDIUM] CWE-472 CVE-2020-1765: An improper control of parameters allows the spoofing of the from fields of the following screens: A An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior v
nvd
CVE-2019-14905P4MEDIUMCVSS 5.6v15.12020-03-31
CVE-2019-14905 [MEDIUM] CWE-20 CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x b A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of con
nvd
CVE-2020-12801P4MEDIUMCVSS 5.3v15.12020-05-18
CVE-2020-12801 [MEDIUM] CWE-311 CVE-2020-12801: If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format of the recovered document was not LibreOffice's default ODF file format, then affected versions of L
nvd
CVE-2020-8624P4MEDIUMCVSS 4.3v15.1v15.22020-08-21
CVE-2020-8624 [MEDIUM] CWE-269 CVE-2020-8624: In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, a In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to upda
nvd
CVE-2019-18901P4MEDIUMCVSS 5.5v15.12020-03-02
CVE-2019-18901 [MEDIUM] CWE-59 CVE-2019-18901: A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb pa A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE Linux Enterprise Server 12 mariadb versions prior to 10.2.31-3.25.1. SUSE
nvd
CVE-2016-7787P4MEDIUMCVSS 4.9v42.12016-12-23
CVE-2016-7787 [MEDIUM] CWE-94 CVE-2016-7787: A maliciously crafted command line for kdesu can result in the user only seeing part of the commands A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
nvd
CVE-2015-7216P4MEDIUMCVSS 6.8v42.12015-12-16
CVE-2015-7216 [MEDIUM] CWE-20 CVE-2015-7216: The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly ena The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.
nvd
CVE-2019-0197P4MEDIUMCVSS 4.2v15.0v42.32019-06-11
CVE-2019-0197 [MEDIUM] CWE-444 CVE-2019-0197: A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled
nvd
CVE-2016-6905P4MEDIUMCVSS 6.5v42.12016-10-03
CVE-2016-6905 [MEDIUM] CWE-125 CVE-2016-6905: The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows r The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.
nvd
CVE-2020-0556P4HIGHCVSS 7.1v15.1v15.22020-03-12
CVE-2020-0556 [HIGH] CVE-2020-0556: Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
nvd
CVE-2016-2822P4MEDIUMCVSS 6.5v42.12016-06-13
CVE-2016-2822 [MEDIUM] CWE-284 CVE-2016-2822: Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the add Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
nvd
CVE-2016-4068P4MEDIUMCVSS 6.1v42.12017-04-13
CVE-2016-4068 [MEDIUM] CVE-2016-4068: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 al Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
nvd
CVE-2019-14383P4MEDIUMCVSS 6.5v15.0v15.12019-07-30
CVE-2019-14383 [MEDIUM] CWE-617 CVE-2019-14383: J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
nvd
CVE-2018-20860P4MEDIUMCVSS 6.5v15.0v15.12019-07-30
CVE-2018-20860 [MEDIUM] CWE-20 CVE-2018-20860: libopenmpt before 0.3.13 allows a crash with malformed MED files. libopenmpt before 0.3.13 allows a crash with malformed MED files.
nvd
Opensuse Leap vulnerabilities | cvebase