cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 78 of 95
CVE-2019-18179P4MEDIUMCVSS 4.3v15.1v15.22020-01-06
CVE-2019-18179 [MEDIUM] CVE-2019-18179: An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edi An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
nvd
CVE-2019-10130P4MEDIUMCVSS 4.3v15.12019-07-30
CVE-2019-10130 [MEDIUM] CWE-284 CVE-2019-10130: A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10. A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evalu
nvd
CVE-2019-11720P4MEDIUMCVSS 6.1v15.0v15.12019-07-23
CVE-2019-11720 [MEDIUM] CWE-79 CVE-2019-11720: Some unicode characters are incorrectly treated as whitespace during the parsing of web content inst Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.
nvd
CVE-2019-5460P4MEDIUMCVSS 5.5v15.0v15.12019-07-30
CVE-2019-5460 [MEDIUM] CWE-415 CVE-2019-5460: Double Free in VLC versions <= 3.0.6 leads to a crash. Double Free in VLC versions <= 3.0.6 leads to a crash.
nvd
CVE-2016-2038P4MEDIUMCVSS 5.3v42.12016-02-20
CVE-2016-2038 [MEDIUM] CWE-200 CVE-2016-2038: phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attac phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
nvd
CVE-2016-2317P4MEDIUMCVSS 5.5v42.12017-02-03
CVE-2016-2317 [MEDIUM] CWE-119 CVE-2016-2317: Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of servi Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.
nvd
CVE-2015-5203P4MEDIUMCVSS 5.5v42.22017-08-02
CVE-2015-5203 [MEDIUM] CWE-415 CVE-2015-5203: Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote at Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
nvd
CVE-2016-2318P4MEDIUMCVSS 5.5v42.12017-02-03
CVE-2016-2318 [MEDIUM] CWE-476 CVE-2016-2318: GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.
nvd
CVE-2019-15142P4MEDIUMCVSS 5.5v15.0v15.12019-08-18
CVE-2019-15142 [MEDIUM] CWE-125 CVE-2019-15142: In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of- In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
nvd
CVE-2020-11760P4MEDIUMCVSS 5.5v15.12020-04-14
CVE-2020-11760 [MEDIUM] CWE-125 CVE-2020-11760: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompres An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
nvd
CVE-2020-11758P4MEDIUMCVSS 5.5v15.12020-04-14
CVE-2020-11758 [MEDIUM] CWE-125 CVE-2020-11758: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixel An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
nvd
CVE-2020-13800P4MEDIUMCVSS 6.0v15.22020-06-04
CVE-2020-13800 [MEDIUM] CWE-674 CVE-2020-13800: ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
nvd
CVE-2016-0647P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0647 [MEDIUM] CVE-2016-0647: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS.
nvd
CVE-2016-0648P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0648 [MEDIUM] CVE-2016-0648: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS.
nvd
CVE-2016-0666P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0666 [MEDIUM] CVE-2016-0666: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to Security: Privileges.
nvd
CVE-2020-25602P4MEDIUMCVSS 6.0v15.22020-09-23
CVE-2020-25602 [MEDIUM] CWE-755 CVE-2020-25602: An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when hand An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen first reads the value from hardware to use as the basis for auditing the guest access. For the MISC_ENABLE MSR, which is an Intel specific MSR, this MSR
nvd
CVE-2019-16167P4MEDIUMCVSS 5.5v15.0v15.12019-09-09
CVE-2019-16167 [MEDIUM] CWE-190 CVE-2019-16167: sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_commo sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
nvd
CVE-2018-19665P4MEDIUMCVSS 5.7v42.32018-12-06
CVE-2018-19665 [MEDIUM] CWE-190 CVE-2018-19665: The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory c The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
nvd
CVE-2016-2043P4MEDIUMCVSS 5.4v42.12016-02-20
CVE-2016-2043 [MEDIUM] CWE-79 CVE-2016-2043: Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in php Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page.
nvd
CVE-2019-15118P4MEDIUMCVSS 5.5v15.0v15.12019-08-16
CVE-2019-15118 [MEDIUM] CWE-674 CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leadin check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
nvd
Opensuse Leap vulnerabilities | cvebase