Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 7 of 95
CVE-2018-8795P3CRITICALCVSS 9.8v15.12019-02-05
CVE-2018-8795 [CRITICAL] CWE-680 CVE-2018-8795: rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory corruption and probably even a remote code execution.
nvd
CVE-2018-8793P3CRITICALCVSS 9.8v15.12019-02-05
CVE-2018-8793 [CRITICAL] CWE-122 CVE-2018-8793: rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_r
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2018-8800P3CRITICALCVSS 9.8v15.12019-02-05
CVE-2018-8800 [CRITICAL] CWE-122 CVE-2018-8800: rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_cli
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2018-10929P3HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10929 [HIGH] CWE-20 CVE-2018-10929: A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
nvd
CVE-2020-12640P3CRITICALCVSS 9.8v15.1v15.22020-05-04
CVE-2020-12640 [CRITICAL] CWE-22 CVE-2020-12640: Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via director
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
nvd
CVE-2018-10926P3HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10926 [HIGH] CWE-20 CVE-2018-10926: A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
nvd
CVE-2018-20346P3HIGHCVSS 8.1v15.0v42.32018-12-21
CVE-2018-20346 [HIGH] CWE-190 CVE-2018-20346: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magell
nvd
CVE-2016-1285P3MEDIUMCVSS 6.8v42.12016-03-09
CVE-2016-1285 [MEDIUM] CVE-2016-1285: named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME rec
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
nvd
CVE-2018-20506P3HIGHCVSS 8.1v42.32019-04-03
CVE-2018-20506 [HIGH] CVE-2018-20506: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use ca
nvd
CVE-2016-4957P3HIGHCVSS 7.5v42.12016-07-05
CVE-2016-4957 [HIGH] CVE-2016-4957: ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
nvd
CVE-2019-12838P3CRITICALCVSS 9.8v15.0v15.12019-07-11
CVE-2019-12838 [CRITICAL] CWE-89 CVE-2019-12838: SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
nvd
CVE-2016-4007P3CRITICALCVSS 9.8v42.12016-04-13
CVE-2016-4007 [CRITICAL] CVE-2016-4007: Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openS
Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to execute arbitrary commands via a service definition, related to executing unzip with "illegal options."
nvd
CVE-2016-5703P3CRITICALCVSS 9.8v42.12016-07-03
CVE-2016-5703 [CRITICAL] CWE-89 CVE-2016-5703: SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.
nvd
CVE-2020-24972P3HIGHCVSS 8.8v15.12020-08-29
CVE-2020-24972 [HIGH] CWE-116 CVE-2020-24972: The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to exe
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
nvd
CVE-2018-8797P3CRITICALCVSS 9.8v15.12019-02-05
CVE-2018-8797 [CRITICAL] CWE-122 CVE-2018-8797: rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function proces
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2016-4303P3CRITICALCVSS 9.8v42.12016-09-26
CVE-2016-4303 [CRITICAL] CWE-120 CVE-2016-4303: The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows r
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
nvd
CVE-2019-12519P3CRITICALCVSS 9.8v15.12020-04-15
CVE-2019-12519 [CRITICAL] CWE-787 CVE-2019-12519: An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Sq
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When addin
nvd
CVE-2017-8834P3MEDIUMCVSS 6.5PoCv42.32017-06-12
CVE-2017-8834 [MEDIUM] CWE-119 CVE-2017-8834: The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to caus
The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
nvd
CVE-2018-10904P3HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10904 [HIGH] CWE-426 CVE-2018-10904: It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-du
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a glus
nvd
CVE-2018-10928P3HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10928 [HIGH] CWE-59 CVE-2018-10928: A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink dest
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
nvd