Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 71 of 95
CVE-2020-6470P4MEDIUMCVSS 6.1v15.12020-05-21
CVE-2020-6470 [MEDIUM] CWE-79 CVE-2020-6470: Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allow
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.
nvd
CVE-2019-13627P4MEDIUMCVSS 6.3v15.0v15.12019-09-25
CVE-2019-13627 [MEDIUM] CWE-203 CVE-2019-13627: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Ver
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
nvd
CVE-2019-2737P4MEDIUMCVSS 4.9v15.12019-07-23
CVE-2019-2737 [MEDIUM] CVE-2019-2737: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2015-5969P4MEDIUMCVSS 6.2v42.12016-04-08
CVE-2015-5969 [MEDIUM] CWE-200 CVE-2015-5969: The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSU
The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Linux Enterprise (SLE) 12.1 and openSUSE Leap 42.1 allows local users to discover database credentials by
nvd
CVE-2016-3992P4MEDIUMCVSS 6.2v42.12016-07-26
CVE-2016-3992 [MEDIUM] CWE-284 CVE-2016-3992: cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.
nvd
CVE-2019-19927P4MEDIUMCVSS 6.0v15.12019-12-31
CVE-2019-19927 [MEDIUM] CWE-125 CVE-2019-19927: In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
nvd
CVE-2020-15025P4MEDIUMCVSS 4.9v15.1v15.22020-06-24
CVE-2020-15025 [MEDIUM] CWE-401 CVE-2020-15025: ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
nvd
CVE-2020-14310P4MEDIUMCVSS 6.0v15.1v15.22020-07-31
CVE-2020-14310 [MEDIUM] CWE-122 CVE-2020-14310: There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a fo
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX,
nvd
CVE-2019-1787P4MEDIUMCVSS 5.5v15.0v42.32019-04-08
CVE-2019-1787 [MEDIUM] CWE-20 CVE-2019-1787: A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (Clam
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of proper data handling mechanisms within the device buffer whi
nvd
CVE-2019-11717P4MEDIUMCVSS 5.3v15.0v15.12019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2019-2975P4MEDIUMCVSS 4.8v15.0v15.12019-10-16
CVE-2019-2975 [MEDIUM] CVE-2019-2975: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attac
nvd
CVE-2019-17021P4MEDIUMCVSS 5.3v15.12020-01-08
CVE-2019-17021 [MEDIUM] CWE-362 CVE-2019-17021: During the initialization of a new content process, a race condition occurs that can allow a content
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2016-1939P4MEDIUMCVSS 5.3v42.12016-01-31
CVE-2016-1939 [MEDIUM] CVE-2016-1939: Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allo
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208.
nvd
CVE-2020-11095P4MEDIUMCVSS 5.4v15.12020-06-22
CVE-2020-11095 [MEDIUM] CWE-125 CVE-2020-11095: In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory locati
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
nvd
CVE-2020-11086P4MEDIUMCVSS 5.4v15.12020-05-29
CVE-2020-11086 [MEDIUM] CWE-125 CVE-2020-11086: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_ch
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to an internal structure. This has been fixed in 2.1.0.
nvd
CVE-2020-11097P4MEDIUMCVSS 5.4v15.12020-06-22
CVE-2020-11097 [MEDIUM] CWE-125 CVE-2020-11097: In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory locati
In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
nvd
CVE-2019-15902P4MEDIUMCVSS 5.6v15.0v15.12019-09-04
CVE-2019-15902 [MEDIUM] CWE-200 CVE-2019-15902: A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate.
nvd
CVE-2019-11718P4MEDIUMCVSS 5.3v15.0v15.12019-07-23
CVE-2019-11718 [MEDIUM] CWE-74 CVE-2019-11718: Activity Stream can display content from sent from the Snippet Service website. This content is writ
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Fire
nvd
CVE-2019-2999P4MEDIUMCVSS 4.7v15.0v15.12019-10-16
CVE-2019-2999 [MEDIUM] CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than th
nvd
CVE-2020-8619P4MEDIUMCVSS 4.9v15.1v15.22020-06-17
CVE-2020-8619 [MEDIUM] CWE-404 CVE-2020-8619: In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND S
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be enco
nvd