cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 77 of 95
CVE-2012-3534P4MEDIUMCVSS 5.0v42.12012-08-31
CVE-2012-3534 [MEDIUM] CWE-119 CVE-2012-3534: GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which allows GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which allows remote attackers to cause a denial of service (connection and thread consumption) via a large number of connections.
nvd
CVE-2016-10070P4MEDIUMCVSS 5.5v42.1v42.22017-03-03
CVE-2016-10070 [MEDIUM] CWE-125 CVE-2016-10070: Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
nvd
CVE-2016-8568P4MEDIUMCVSS 5.5v42.1v42.22017-02-03
CVE-2016-8568 [MEDIUM] CWE-125 CVE-2016-8568: The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
nvd
CVE-2020-11762P4MEDIUMCVSS 5.5v15.12020-04-14
CVE-2020-11762 [MEDIUM] CWE-125 CVE-2020-11762: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaComp An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
nvd
CVE-2020-11763P4MEDIUMCVSS 5.5v15.12020-04-14
CVE-2020-11763 [MEDIUM] CWE-125 CVE-2020-11763: An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and writ An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
nvd
CVE-2015-7219P4MEDIUMCVSS 5.0v42.12015-12-16
CVE-2015-7219 [MEDIUM] CWE-189 CVE-2015-7219: The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial o The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length miscalculation and incorrect memory allocation.
nvd
CVE-2019-11459P4MEDIUMCVSS 5.5v15.0v15.12019-04-22
CVE-2019-11459 [MEDIUM] CWE-754 CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
nvd
CVE-2019-9209P4MEDIUMCVSS 5.5v15.0v15.1+1 more2019-02-28
CVE-2019-9209 [MEDIUM] CWE-193 CVE-2019-9209: In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. T In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
nvd
CVE-2019-2628P4MEDIUMCVSS 4.9v15.0v15.12019-04-23
CVE-2019-2628 [MEDIUM] CVE-2019-2628: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2020-16166P4LOWCVSS 3.7v15.1v15.22020-07-30
CVE-2020-16166 [LOW] CWE-330 CVE-2020-16166: The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sen The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
nvd
CVE-2020-26164P4MEDIUMCVSS 5.5v15.1v15.22020-10-07
CVE-2020-26164 [MEDIUM] CWE-400 CVE-2020-26164: In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send craf In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
nvd
CVE-2018-16597P4MEDIUMCVSS 5.5v42.32018-09-21
CVE-2018-16597 [MEDIUM] CWE-863 CVE-2018-16597: An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mount An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
nvd
CVE-2020-0543P4MEDIUMCVSS 5.5v15.1v15.22020-06-15
CVE-2020-0543 [MEDIUM] CWE-459 CVE-2020-0543: Incomplete cleanup from specific special register read operations in some Intel(R) Processors may al Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2020-26088P4MEDIUMCVSS 5.5v15.1v15.22020-09-24
CVE-2020-26088 [MEDIUM] CWE-276 CVE-2020-26088: A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5 A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
nvd
CVE-2020-25641P4MEDIUMCVSS 5.5v15.1v15.22020-10-06
CVE-2020-25641 [MEDIUM] CWE-835 CVE-2020-25641: A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero- A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of se
nvd
CVE-2019-19727P4MEDIUMCVSS 5.5v15.12020-01-13
CVE-2019-19727 [MEDIUM] CWE-732 CVE-2019-19727: SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions. SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
nvd
CVE-2016-1947P4MEDIUMCVSS 4.7v42.12016-01-31
CVE-2016-1947 [MEDIUM] CWE-19 CVE-2016-1947: Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which mak Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
nvd
CVE-2019-2745P4MEDIUMCVSS 5.1v15.0v15.12019-07-23
CVE-2019-2745 [MEDIUM] CVE-2019-2745: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported version Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks of this vulnerability can result in un
nvd
CVE-2019-15920P4MEDIUMCVSS 4.3v15.0v15.12019-09-04
CVE-2019-15920 [MEDIUM] CWE-416 CVE-2019-15920: An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use- An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use-after-free. NOTE: this was not fixed correctly in 5.0.10; see the 5.0.11 ChangeLog, which documents a memory leak.
nvd
CVE-2020-6441P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6441 [MEDIUM] CWE-276 CVE-2020-6441: Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote a Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
nvd
Opensuse Leap vulnerabilities | cvebase