cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 73 of 95
CVE-2020-8834P4MEDIUMCVSS 6.5v15.12020-04-09
CVE-2020-8834 [MEDIUM] CWE-368 CVE-2020-8834: KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 sta KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to panic. There were two commits that, according to the
nvd
CVE-2016-5705P4MEDIUMCVSS 6.1v42.12016-07-03
CVE-2016-5705 [MEDIUM] CWE-79 CVE-2016-5705: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x be Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) server-privileges certificate data fields on the user privileges page, (2) an "invalid JSON" error message in the error console, (3) a database name in the
nvd
CVE-2017-5938P4MEDIUMCVSS 6.1v42.22017-03-15
CVE-2017-5938 [MEDIUM] CWE-79 CVE-2017-5938: Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.
nvd
CVE-2016-1937P4MEDIUMCVSS 6.1v42.12016-01-31
CVE-2016-1937 [MEDIUM] CWE-79 CVE-2016-1937: The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickj The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
nvd
CVE-2018-13096P4MEDIUMCVSS 5.5v42.32018-07-03
CVE-2018-13096 [MEDIUM] CWE-125 CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (ou An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon encountering an abnormal bitmap size when mounting a crafted f2fs image.
nvd
CVE-2019-6454P4MEDIUMCVSS 5.5v15.02019-03-21
CVE-2019-6454 [MEDIUM] CWE-787 CVE-2019-6454: An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-obje An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the sta
nvd
CVE-2020-6516P4MEDIUMCVSS 4.3v15.1v15.22020-07-22
CVE-2020-6516 [MEDIUM] CVE-2020-6516: Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-16062P4MEDIUMCVSS 5.5v15.0v15.12018-08-29
CVE-2018-16062 [MEDIUM] CWE-125 CVE-2018-16062: dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attacker dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
nvd
CVE-2020-14311P4MEDIUMCVSS 6.0v15.1v15.22020-07-31
CVE-2020-14311 [MEDIUM] CWE-122 CVE-2020-14311: There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesy There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.
nvd
CVE-2020-8649P4MEDIUMCVSS 5.9v15.12020-02-06
CVE-2020-8649 [MEDIUM] CWE-416 CVE-2020-8649: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_regio There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
nvd
CVE-2015-7211P4MEDIUMCVSS 5.0v42.12015-12-16
CVE-2015-7211 [MEDIUM] CWE-20 CVE-2015-7211: Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows re Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.
nvd
CVE-2019-14275P4MEDIUMCVSS 5.5v15.1v15.22019-07-26
CVE-2019-14275 [MEDIUM] CWE-787 CVE-2019-14275: Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
nvd
CVE-2020-11088P4MEDIUMCVSS 5.4v15.12020-05-29
CVE-2020-11088 [MEDIUM] CWE-125 CVE-2020-11088: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.
nvd
CVE-2020-11087P4MEDIUMCVSS 5.4v15.12020-05-29
CVE-2020-11087 [MEDIUM] CWE-125 CVE-2020-11087: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessa In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.
nvd
CVE-2020-11089P4MEDIUMCVSS 5.5v15.12020-05-29
CVE-2020-11089 [MEDIUM] CWE-125 CVE-2020-11089: In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0.
nvd
CVE-2015-8792P4MEDIUMCVSS 5.3v42.12016-01-29
CVE-2015-8792 [MEDIUM] CWE-119 CVE-2015-8792: The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attacke The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process heap memory via crafted EBML lacing, which triggers an invalid memory access.
nvd
CVE-2019-14847P4MEDIUMCVSS 4.9v15.02019-11-06
CVE-2019-14847 [MEDIUM] CWE-476 CVE-2019-14847: A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.
nvd
CVE-2019-7308P4MEDIUMCVSS 5.6v15.02019-02-01
CVE-2019-7308 [MEDIUM] CWE-189 CVE-2019-7308: kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculati kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.
nvd
CVE-2016-1692P4MEDIUMCVSS 5.3v42.12016-06-05
CVE-2016-1692 [MEDIUM] CWE-284 CVE-2016-1692: WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63 WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2020-13844P4MEDIUMCVSS 5.5v15.1v15.22020-06-08
CVE-2020-13844 [MEDIUM] CWE-203 CVE-2020-13844: Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in contr Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
nvd
Opensuse Leap vulnerabilities | cvebase