cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 80 of 95
CVE-2020-14700P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14700 [MEDIUM] CWE-125 CVE-2020-14700: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Vi
nvd
CVE-2020-14648P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14648 [MEDIUM] CVE-2020-14648: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
nvd
CVE-2020-14698P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14698 [MEDIUM] CWE-125 CVE-2020-14698: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Vi
nvd
CVE-2020-14695P4MEDIUMCVSS 5.3v15.1v15.22020-07-15
CVE-2020-14695 [MEDIUM] CWE-125 CVE-2020-14695: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM Vi
nvd
CVE-2019-3811P4MEDIUMCVSS 5.2v15.0v42.32019-01-15
CVE-2019-3811 [MEDIUM] CWE-200 CVE-2019-3811: A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would r A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
nvd
CVE-2020-5267P4MEDIUMCVSS 4.8v15.12020-03-19
CVE-2020-5267 [MEDIUM] CWE-80 CVE-2020-5267: In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionVi In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.
nvd
CVE-2015-4830P4MEDIUMCVSS 4.0v42.12015-10-21
CVE-2015-4830 [MEDIUM] CVE-2015-4830: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2020-0093P4MEDIUMCVSS 5.0v15.12020-05-14
CVE-2020-0093 [MEDIUM] CWE-125 CVE-2020-0093: In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
nvd
CVE-2020-4032P4MEDIUMCVSS 4.3v15.12020-06-22
CVE-2020-4032 [MEDIUM] CWE-681 CVE-2020-4032: In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_ In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
nvd
CVE-2019-18660P4MEDIUMCVSS 4.7v15.12019-11-27
CVE-2019-18660 [MEDIUM] CWE-200 CVE-2019-18660: The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigat The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
nvd
CVE-2020-6437P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6437 [MEDIUM] CVE-2020-6437: Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote atta Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
nvd
CVE-2020-6527P4MEDIUMCVSS 4.3v15.1v15.22020-07-22
CVE-2020-6527 [MEDIUM] CWE-276 CVE-2020-6527: Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attac Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-1769P4MEDIUMCVSS 4.3v15.1v15.22020-03-27
CVE-2020-1769 [MEDIUM] CWE-16 CVE-2020-1769: In the login screens (in agent and customer interface), Username and Password fields use autocomplet In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
nvd
CVE-2019-5839P4MEDIUMCVSS 4.3v15.0v15.1+1 more2019-06-27
CVE-2019-5839 [MEDIUM] CWE-20 CVE-2019-5839: Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote atta Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
nvd
CVE-2019-12973P4MEDIUMCVSS 5.5v15.0v15.12019-06-26
CVE-2019-12973 [MEDIUM] CVE-2019-12973: In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
nvd
CVE-2016-4804P4MEDIUMCVSS 6.2v42.12016-06-03
CVE-2016-4804 [MEDIUM] CWE-119 CVE-2016-4804: The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of serv The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
nvd
CVE-2015-5221P4MEDIUMCVSS 5.5v42.22017-07-25
CVE-2015-5221 [MEDIUM] CWE-416 CVE-2015-5221: Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasP Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
nvd
CVE-2016-8688P4MEDIUMCVSS 5.5v42.22017-02-15
CVE-2016-8688 [MEDIUM] CWE-125 CVE-2016-8688: The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
nvd
CVE-2014-9845P4MEDIUMCVSS 5.5v42.22017-03-20
CVE-2014-9845 [MEDIUM] CWE-119 CVE-2014-9845: The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial o The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
nvd
CVE-2016-8569P4MEDIUMCVSS 5.5v42.1v42.22017-02-03
CVE-2016-8569 [MEDIUM] CWE-476 CVE-2016-8569: The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a de The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
nvd
Opensuse Leap vulnerabilities | cvebase