cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 72 of 95
CVE-2020-10942P4MEDIUMCVSS 5.3v15.12020-03-24
CVE-2020-10942 [MEDIUM] CWE-787 CVE-2020-10942: In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_fa In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
nvd
CVE-2019-3812P4MEDIUMCVSS 5.5v42.32019-02-19
CVE-2019-3812 [MEDIUM] CWE-119 CVE-2019-3812: QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up t QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the host.
nvd
CVE-2020-15204P4MEDIUMCVSS 5.3v15.22020-09-25
CVE-2020-15204 [MEDIUM] CWE-476 CVE-2020-15204: In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the ses In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, calling `tf.raw_ops.GetSessionHandle` or `tf.raw_ops.GetSessionHandleV2` results in a null pointer dereference In linked snippet, in eager mode, `ctx->session_state()` returns `nullptr`. Since code immediately dereferences this, we
nvd
CVE-2020-2767P4MEDIUMCVSS 4.8v15.12020-04-15
CVE-2020-2767 [MEDIUM] CVE-2020-2767: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to
nvd
CVE-2020-8618P4MEDIUMCVSS 4.9v15.1v15.22020-06-17
CVE-2020-8618 [MEDIUM] CWE-617 CVE-2020-8618: An attacker who is permitted to send zone data to a server via zone transfer can exploit this to int An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
nvd
CVE-2019-9849P4MEDIUMCVSS 4.3v15.0v15.12019-07-17
CVE-2019-9849 [MEDIUM] CVE-2019-9849: LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior t
nvd
CVE-2016-10739P4MEDIUMCVSS 5.3v15.02019-01-21
CVE-2016-10739 [MEDIUM] CWE-20 CVE-2016-10739: In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially d
nvd
CVE-2018-10360P4MEDIUMCVSS 6.5v15.0v42.32018-06-11
CVE-2018-10360 [MEDIUM] CWE-125 CVE-2018-10360: The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
nvd
CVE-2019-13311P4MEDIUMCVSS 6.5v15.0v15.12019-07-05
CVE-2019-13311 [MEDIUM] CWE-401 CVE-2019-13311: ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error. ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
nvd
CVE-2019-13301P4MEDIUMCVSS 6.5v15.0v15.12019-07-05
CVE-2019-13301 [MEDIUM] CWE-401 CVE-2019-13301: ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error. ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
nvd
CVE-2019-13309P4MEDIUMCVSS 6.5v15.0v15.12019-07-05
CVE-2019-13309 [MEDIUM] CWE-401 CVE-2019-13309: ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchIm ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
nvd
CVE-2015-5828P4MEDIUMCVSS 4.3v42.12015-10-09
CVE-2015-5828 [MEDIUM] CWE-20 CVE-2015-5828: The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of a The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.
nvd
CVE-2019-13310P4MEDIUMCVSS 6.5v15.0v15.12019-07-05
CVE-2019-13310 [MEDIUM] CWE-401 CVE-2019-13310: ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/m ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
nvd
CVE-2020-12625P4MEDIUMCVSS 6.1v15.1v15.22020-05-04
CVE-2020-12625 [MEDIUM] CWE-79 CVE-2020-12625: An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vul An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
nvd
CVE-2019-19081P4MEDIUMCVSS 5.9v15.12019-11-18
CVE-2019-19081 [MEDIUM] CWE-401 CVE-2019-19081: A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/fl A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allows attackers to cause a denial of service (memory consumption), aka CID-8ce39eb5a67a.
nvd
CVE-2020-6611P4MEDIUMCVSS 6.5v15.12020-01-08
CVE-2020-6611 [MEDIUM] CWE-476 CVE-2020-6611: GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c. GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
nvd
CVE-2020-6615P4MEDIUMCVSS 6.5v15.12020-01-08
CVE-2020-6615 [MEDIUM] CWE-476 CVE-2020-6615: GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (d GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
nvd
CVE-2016-1689P4MEDIUMCVSS 6.5v42.12016-06-05
CVE-2016-1689 [MEDIUM] CWE-119 CVE-2016-1689: Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome befo Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2016-5731P4MEDIUMCVSS 6.1v42.12016-07-03
CVE-2016-5731 [MEDIUM] CWE-79 CVE-2016-5731: Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16 Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error message.
nvd
CVE-2020-14711P4MEDIUMCVSS 6.5v15.1v15.22020-07-15
CVE-2020-14711 [MEDIUM] CVE-2020-14711: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
nvd
Opensuse Leap vulnerabilities | cvebase