Opensuse Leap vulnerabilities

1,896 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,896
CISA KEV
18
actively exploited
Public exploits
57
Exploited in wild
19
Severity breakdown
CRITICAL202HIGH798MEDIUM803LOW93

Vulnerabilities

Page 70 of 95
CVE-2018-18544MEDIUMCVSS 6.5v15.02018-10-21
CVE-2018-18544 [MEDIUM] CWE-772 CVE-2018-18544: There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, an There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
nvd
CVE-2018-18521MEDIUMCVSS 5.5v15.0v15.12018-10-19
CVE-2018-18521 [MEDIUM] CWE-369 CVE-2018-18521: Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allo Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.
nvd
CVE-2018-18520MEDIUMCVSS 6.5v15.0v15.12018-10-19
CVE-2018-18520 [MEDIUM] CWE-119 CVE-2018-18520: An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted
nvd
CVE-2017-5934MEDIUMCVSS 6.1v15.0v42.32018-10-15
CVE-2017-5934 [MEDIUM] CWE-79 CVE-2017-5934: Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.1 Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2018-18310MEDIUMCVSS 5.5v15.0v15.12018-10-15
CVE-2018-18310 [MEDIUM] CWE-119 CVE-2018-18310: An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in e An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes.
nvd
CVE-2018-18225HIGHCVSS 7.5v15.12018-10-12
CVE-2018-18225 [HIGH] CWE-682 CVE-2018-18225: In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/p In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
nvd
CVE-2018-18074HIGHCVSS 7.5v15.12018-10-09
CVE-2018-18074 [HIGH] CWE-522 CVE-2018-18074: The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
nvd
CVE-2018-12477HIGHCVSS 7.5v15.0v42.32018-10-09
CVE-2018-12477 [HIGH] CWE-93 CVE-2018-12477: A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attack A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versions prior to d6244245dda5367767efc989446fe4b5e4609cce.
nvd
CVE-2018-14647HIGHCVSS 7.5v15.12018-09-25
CVE-2018-14647 [HIGH] CWE-335 CVE-2018-14647: Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. Thi Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in P
nvd
CVE-2018-17294MEDIUMCVSS 6.5v15.02018-09-21
CVE-2018-17294 [MEDIUM] CWE-125 CVE-2018-17294: The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.
nvd
CVE-2018-16597MEDIUMCVSS 5.5v42.32018-09-21
CVE-2018-16597 [MEDIUM] CWE-863 CVE-2018-16597: An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mount An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
nvd
CVE-2018-1000802CRITICALCVSS 9.8v15.12018-09-18
CVE-2018-1000802 [CRITICAL] CWE-77 CVE-2018-1000802: Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization o Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack a
nvd
CVE-2018-10928HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10928 [HIGH] CWE-59 CVE-2018-10928: A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink dest A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
nvd
CVE-2018-10904HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10904 [HIGH] CWE-426 CVE-2018-10904: It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-du It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a glus
nvd
CVE-2018-10929HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10929 [HIGH] CWE-20 CVE-2018-10929: A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
nvd
CVE-2018-10907HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10907 [HIGH] CWE-121 CVE-2018-10907: It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to fun It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.
nvd
CVE-2018-10927HIGHCVSS 8.1v15.12018-09-04
CVE-2018-10927 [HIGH] CWE-20 CVE-2018-10927: A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
nvd
CVE-2018-10923HIGHCVSS 8.1v15.12018-09-04
CVE-2018-10923 [HIGH] CWE-20 CVE-2018-10923: It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a g It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
nvd
CVE-2018-10911HIGHCVSS 7.5v15.12018-09-04
CVE-2018-10911 [HIGH] CWE-190 CVE-2018-10911: A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key lengt A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
nvd
CVE-2018-10926HIGHCVSS 8.8v15.12018-09-04
CVE-2018-10926 [HIGH] CWE-20 CVE-2018-10926: A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
nvd