cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 74 of 95
CVE-2016-1694P4MEDIUMCVSS 5.3v42.12016-06-05
CVE-2016-1694 [MEDIUM] CWE-284 CVE-2016-1694: browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pin browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority.
nvd
CVE-2020-5202P4MEDIUMCVSS 5.5v15.12020-01-21
CVE-2020-5202 [MEDIUM] CVE-2020-5202: apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardco apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-n
nvd
CVE-2020-15190P4MEDIUMCVSS 5.3v15.22020-09-25
CVE-2020-15190 [MEDIUM] CWE-20 CVE-2020-15190: In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operati In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outputs two tensors. Depending on the boolean value, one of the tensors is exactly the input tensor whereas the other one should be an empty tensor. However, the eager runtime traverses all tensors in the ou
nvd
CVE-2018-20105P4MEDIUMCVSS 5.5v15.0≥ yast2-rmt, < 1.2.22020-01-27
CVE-2018-20105 [MEDIUM] CWE-532 CVE-2018-20105: A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterpris A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
nvd
CVE-2020-15191P4MEDIUMCVSS 5.3v15.22020-09-25
CVE-2020-15191 [MEDIUM] CWE-20 CVE-2020-15191: In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dl In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variables to bind to `nullptr` while setting a `status` variable to the error condition. However, this `status` argument is not properly checked. Hence, code following these methods will bind references to null
nvd
CVE-2019-18391P4MEDIUMCVSS 5.5v15.12019-12-23
CVE-2019-18391 [MEDIUM] CWE-787 CVE-2019-18391: A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c i A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
nvd
CVE-2015-7542P4MEDIUMCVSS 5.3v42.2v42.32019-12-03
CVE-2015-7542 [MEDIUM] CWE-319 CVE-2015-7542: A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certi A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
nvd
CVE-2015-7217P4MEDIUMCVSS 4.3v42.12015-12-16
CVE-2015-7217 [MEDIUM] CWE-119 CVE-2015-7217: The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly ena The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.
nvd
CVE-2019-16709P4MEDIUMCVSS 6.5v15.0v15.12019-09-23
CVE-2019-16709 [MEDIUM] CWE-401 CVE-2019-16709: ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
nvd
CVE-2019-17450P4MEDIUMCVSS 6.5v15.1v15.22019-10-10
CVE-2019-17450 [MEDIUM] CWE-674 CVE-2019-17450: find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as dist find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
nvd
CVE-2018-17294P4MEDIUMCVSS 6.5v15.02018-09-21
CVE-2018-17294 [MEDIUM] CWE-125 CVE-2018-17294: The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.
nvd
CVE-2020-15211P4MEDIUMCVSS 4.8v15.22020-09-25
CVE-2020-15211 [MEDIUM] CWE-125 CVE-2020-15211: In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbu In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices for the tensors, indexing into an array of tensors t
nvd
CVE-2018-18544P4MEDIUMCVSS 6.5v15.02018-10-21
CVE-2018-18544 [MEDIUM] CWE-772 CVE-2018-18544: There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, an There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
nvd
CVE-2015-5479P4MEDIUMCVSS 6.5v42.12016-04-19
CVE-2015-5479 [MEDIUM] CWE-189 CVE-2015-5479: The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attack The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.
nvd
CVE-2019-11010P4MEDIUMCVSS 6.5v15.0v42.32019-04-08
CVE-2019-11010 [MEDIUM] CWE-401 CVE-2019-11010: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of c In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
nvd
CVE-2016-1685P4MEDIUMCVSS 6.5v42.12016-06-05
CVE-2016-1685 [MEDIUM] CWE-119 CVE-2016-1685: core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates c core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
nvd
CVE-2016-1654P4MEDIUMCVSS 6.5v42.12016-04-18
CVE-2016-1654 [MEDIUM] CWE-20 CVE-2016-1654: The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data str The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
nvd
CVE-2019-2848P4MEDIUMCVSS 6.5v15.0v15.12019-07-23
CVE-2019-2848 [MEDIUM] CVE-2019-2848: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulne
nvd
CVE-2016-2833P4MEDIUMCVSS 6.1v42.12016-06-13
CVE-2016-2833 [MEDIUM] CWE-79 CVE-2016-2833: Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java a Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.
nvd
CVE-2020-2951P4MEDIUMCVSS 6.5v15.12020-04-15
CVE-2020-2951 [MEDIUM] CVE-2020-2951: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whil
nvd
Opensuse Leap vulnerabilities | cvebase