cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 75 of 95
CVE-2019-11724P4MEDIUMCVSS 6.1v15.0v15.12019-07-23
CVE-2019-11724 [MEDIUM] CWE-863 CVE-2019-11724: Application permissions give additional remote troubleshooting permission to the site input.mozilla. Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68.
nvd
CVE-2016-1652P4MEDIUMCVSS 6.1v42.12016-04-18
CVE-2016-1652 [MEDIUM] CWE-79 CVE-2016-1652: Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensio Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvd
CVE-2018-13099P4MEDIUMCVSS 5.5v42.32018-07-03
CVE-2018-13099 [MEDIUM] CWE-125 CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (ou An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.
nvd
CVE-2019-11556P4MEDIUMCVSS 6.1v15.12020-09-25
CVE-2019-11556 [MEDIUM] CWE-79 CVE-2019-11556: Pagure before 5.6 allows XSS via the templates/blame.html blame view. Pagure before 5.6 allows XSS via the templates/blame.html blame view.
nvd
CVE-2019-14250P4MEDIUMCVSS 5.5v15.0v15.1+1 more2019-07-24
CVE-2019-14250 [MEDIUM] CWE-190 CVE-2019-14250: An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_mat An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
nvd
CVE-2020-2741P4MEDIUMCVSS 6.0v15.12020-04-15
CVE-2020-2741 [MEDIUM] CWE-125 CVE-2020-2741: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virtual
nvd
CVE-2020-2894P4MEDIUMCVSS 6.0v15.12020-04-15
CVE-2020-2894 [MEDIUM] CVE-2020-2894: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Whi
nvd
CVE-2020-2743P4MEDIUMCVSS 6.0v15.12020-04-15
CVE-2020-2743 [MEDIUM] CWE-125 CVE-2020-2743: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virtual
nvd
CVE-2020-14704P4MEDIUMCVSS 6.0v15.1v15.22020-07-15
CVE-2020-14704 [MEDIUM] CWE-908 CVE-2020-14704: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virt
nvd
CVE-2020-14703P4MEDIUMCVSS 6.0v15.1v15.22020-07-15
CVE-2020-14703 [MEDIUM] CWE-908 CVE-2020-14703: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Virt
nvd
CVE-2020-14629P4MEDIUMCVSS 6.0v15.1v15.22020-07-15
CVE-2020-14629 [MEDIUM] CVE-2020-14629: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
nvd
CVE-2019-12972P4MEDIUMCVSS 5.5v15.1v15.22019-06-26
CVE-2019-12972 [MEDIUM] CWE-125 CVE-2019-12972: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a trailing '\0' character.
nvd
CVE-2020-11764P4MEDIUMCVSS 5.5v15.12020-04-14
CVE-2020-11764 [MEDIUM] CWE-787 CVE-2020-11764: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuf An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
nvd
CVE-2019-17595P4MEDIUMCVSS 5.4v15.0v15.12019-10-14
CVE-2019-17595 [MEDIUM] CWE-125 CVE-2019-17595: There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminf There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
nvd
CVE-2016-0650P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0650 [MEDIUM] CVE-2016-0650: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to Replication.
nvd
CVE-2016-0649P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0649 [MEDIUM] CVE-2016-0649: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to PS.
nvd
CVE-2016-0644P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0644 [MEDIUM] CVE-2016-0644: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DDL.
nvd
CVE-2016-0646P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0646 [MEDIUM] CVE-2016-0646: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.
nvd
CVE-2019-14274P4MEDIUMCVSS 5.5v15.12019-07-26
CVE-2019-14274 [MEDIUM] CWE-787 CVE-2019-14274: MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
nvd
CVE-2015-7207P4MEDIUMCVSS 5.0v42.12015-12-16
CVE-2015-7207 [MEDIUM] CWE-200 CVE-2015-7207: Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing AP Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
nvd
Opensuse Leap vulnerabilities | cvebase