Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 79 of 95
CVE-2020-10029P4MEDIUMCVSS 5.5v15.12020-03-04
CVE-2020-10029 [MEDIUM] CWE-787 CVE-2020-10029: The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range re
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
nvd
CVE-2016-1693P4MEDIUMCVSS 5.3v42.12016-06-05
CVE-2016-1693 [MEDIUM] CWE-284 CVE-2016-1693: browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the H
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.
nvd
CVE-2020-0549P4MEDIUMCVSS 5.5v15.12020-01-28
CVE-2020-0549 [MEDIUM] CWE-404 CVE-2020-0549: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2016-0596P4MEDIUMCVSS 4.0v42.12016-01-21
CVE-2016-0596 [MEDIUM] CVE-2016-0596: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB befo
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2016-0597P4MEDIUMCVSS 4.0v42.12016-01-21
CVE-2016-0597 [MEDIUM] CVE-2016-0597: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2019-3882P4MEDIUMCVSS 5.5v15.0v15.1+1 more2019-04-24
CVE-2019-3882 [MEDIUM] CWE-770 CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the u
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.
nvd
CVE-2018-18954P4MEDIUMCVSS 5.5v42.32018-11-15
CVE-2018-18954 [MEDIUM] CWE-125 CVE-2018-18954: The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or re
The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
nvd
CVE-2020-15306P4MEDIUMCVSS 5.5v15.1v15.22020-06-26
CVE-2020-15306 [MEDIUM] CWE-787 CVE-2020-15306: An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap b
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
nvd
CVE-2020-25600P4MEDIUMCVSS 5.5v15.22020-09-23
CVE-2020-25600 [MEDIUM] CWE-787 CVE-2020-25600: An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit
An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness) ones. 32-bit x86 domains can use only 1023 channels, due to limited space in
nvd
CVE-2020-25601P4MEDIUMCVSS 5.5v15.22020-09-23
CVE-2020-25601 [MEDIUM] CVE-2020-25601: An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evt
An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active at a time. Closing all of these (when resetting all event channels or when cleaning up after the guest) may take extended periods of time.
nvd
CVE-2015-4802P4MEDIUMCVSS 4.0v42.12015-10-21
CVE-2015-4802 [MEDIUM] CVE-2015-4802: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792.
nvd
CVE-2016-0641P4MEDIUMCVSS 5.1v42.12016-04-21
CVE-2016-0641 [MEDIUM] CVE-2016-0641: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.
nvd
CVE-2016-4036P4MEDIUMCVSS 5.5v42.12016-04-18
CVE-2016-4036 [MEDIUM] CWE-264 CVE-2016-4036: The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses we
The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows local users to obtain sensitive information by reading files in the directory.
nvd
CVE-2016-2383P4MEDIUMCVSS 5.5v42.12016-04-27
CVE-2016-2383 [MEDIUM] CVE-2016-2383: The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consid
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
nvd
CVE-2020-8632P4MEDIUMCVSS 5.5v15.12020-02-05
CVE-2020-8632 [MEDIUM] CWE-521 CVE-2020-8632: In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small d
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
nvd
CVE-2020-12656P4MEDIUMCVSS 5.5v15.1v15.22020-05-05
CVE-2020-12656 [MEDIUM] CWE-401 CVE-2020-12656: gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the
gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue does not grant any access not already available. It is a problem that on unloading a specific kernel mod
nvd
CVE-2015-4858P4MEDIUMCVSS 4.0v42.12015-10-21
CVE-2015-4858 [MEDIUM] CVE-2015-4858: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-4913.
nvd
CVE-2020-14673P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14673 [MEDIUM] CVE-2020-14673: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
nvd
CVE-2020-14694P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14694 [MEDIUM] CWE-125 CVE-2020-14694: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Vi
nvd
CVE-2020-14650P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14650 [MEDIUM] CVE-2020-14650: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
nvd