cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 70 of 95
CVE-2020-15194P4MEDIUMCVSS 5.3v15.22020-09-25
CVE-2020-15194 [MEDIUM] CWE-20 CVE-2020-15194: In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` i In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_t` and `grad_values_t` are accessed in a similar pattern, only `reverse_index_map_t` is validated to be of proper shape. Hence, malicious users can pass
nvd
CVE-2018-18520P4MEDIUMCVSS 6.5v15.0v15.12018-10-19
CVE-2018-18520 [MEDIUM] CWE-119 CVE-2018-18520: An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted
nvd
CVE-2016-6161P4MEDIUMCVSS 6.5v42.12016-08-12
CVE-2016-6161 [MEDIUM] CWE-125 CVE-2016-6161: The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers t The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
nvd
CVE-2019-16710P4MEDIUMCVSS 6.5v15.0v15.12019-09-23
CVE-2019-16710 [MEDIUM] CWE-401 CVE-2019-16710: ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in Ma ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
nvd
CVE-2019-16713P4MEDIUMCVSS 6.5v15.0v15.12019-09-23
CVE-2019-16713 [MEDIUM] CWE-401 CVE-2019-16713: ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/c ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
nvd
CVE-2019-15141P4MEDIUMCVSS 6.5v15.0v15.12019-08-18
CVE-2019-15141 [MEDIUM] CVE-2019-15141: WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-se WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec, and TIFFWriteDirectoryTagColormap in tif_dirwrite.c of LibTIFF. NOTE: this occurs
nvd
CVE-2019-11474P4MEDIUMCVSS 6.5v15.0v42.32019-04-23
CVE-2019-11474 [MEDIUM] CVE-2019-11474: coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
nvd
CVE-2019-13296P4MEDIUMCVSS 6.5v15.0v15.12019-07-05
CVE-2019-13296 [MEDIUM] CWE-401 CVE-2019-13296: ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLILi ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value.
nvd
CVE-2016-1688P4MEDIUMCVSS 6.5v42.12016-06-05
CVE-2016-1688 [MEDIUM] CWE-119 CVE-2016-1688: The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.
nvd
CVE-2018-19542P4MEDIUMCVSS 6.5v15.02018-11-26
CVE-2018-19542 [MEDIUM] CWE-476 CVE-2018-19542: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_de An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
nvd
CVE-2020-6610P4MEDIUMCVSS 6.5v15.12020-01-08
CVE-2020-6610 [MEDIUM] CWE-770 CVE-2020-6610: GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_ GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
nvd
CVE-2016-1686P4MEDIUMCVSS 6.5v42.12016-06-05
CVE-2016-1686 [MEDIUM] CWE-119 CVE-2016-1686: The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2019-19531P4MEDIUMCVSS 6.8v15.12019-12-03
CVE-2019-19531 [MEDIUM] CWE-416 CVE-2019-19531: In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious US In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, aka CID-fc05481b2fca.
nvd
CVE-2017-5934P4MEDIUMCVSS 6.1v15.0v42.32018-10-15
CVE-2017-5934 [MEDIUM] CWE-79 CVE-2017-5934: Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.1 Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2019-20479P4MEDIUMCVSS 6.1v15.12020-02-20
CVE-2019-20479 [MEDIUM] CWE-601 CVE-2019-20479: A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs wit A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
nvd
CVE-2019-15939P4MEDIUMCVSS 5.9v15.12019-09-05
CVE-2019-15939 [MEDIUM] CWE-369 CVE-2019-15939: An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDe An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modules/objdetect/src/hog.cpp.
nvd
CVE-2015-8010P4MEDIUMCVSS 6.1v42.22017-03-27
CVE-2015-8010 [MEDIUM] CWE-79 CVE-2015-8010: Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination f Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.
nvd
CVE-2016-0640P4MEDIUMCVSS 6.1v42.12016-04-21
CVE-2016-0640 [MEDIUM] CVE-2016-0640: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML.
nvd
CVE-2020-15563P4MEDIUMCVSS 6.5v15.22020-07-07
CVE-2020-15563 [MEDIUM] CWE-119 CVE-2020-15563: An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A malicious or buggy HVM guest may cause the hypervisor to crash, resulting i
nvd
CVE-2016-5164P4MEDIUMCVSS 6.1v42.12016-09-11
CVE-2016-5164 [MEDIUM] CWE-79 CVE-2016-5164: Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Bl Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML into the Developer Tools (aka DevTools) subsystem via a crafted web site, aka "Universa
nvd
Opensuse Leap vulnerabilities | cvebase