Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 81 of 95
CVE-2016-9830P4MEDIUMCVSS 5.5v42.1v42.22017-03-01
CVE-2016-9830 [MEDIUM] CWE-20 CVE-2016-9830: The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a d
The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in a jpeg image.
nvd
CVE-2019-15143P4MEDIUMCVSS 5.5v15.0v15.12019-08-18
CVE-2019-15143 [MEDIUM] CWE-835 CVE-2019-15143: In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
nvd
CVE-2020-11765P4MEDIUMCVSS 5.5v15.12020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2016-7994P4MEDIUMCVSS 6.0v42.22016-12-10
CVE-2016-7994 [MEDIUM] CWE-772 CVE-2016-7994: Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Qu
Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_CREATE_2D commands.
nvd
CVE-2015-7218P4MEDIUMCVSS 5.0v42.12015-12-16
CVE-2015-7218 [MEDIUM] CWE-189 CVE-2015-7218: The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial o
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.
nvd
CVE-2014-9756P4MEDIUMCVSS 5.0v42.12015-11-19
CVE-2014-9756 [MEDIUM] CWE-369 CVE-2014-9756: The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (di
The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.
nvd
CVE-2016-6153P4MEDIUMCVSS 5.9v42.12016-09-26
CVE-2016-6153 [MEDIUM] CWE-20 CVE-2016-6153: os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, wh
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.
nvd
CVE-2019-7150P4MEDIUMCVSS 5.5v15.0v15.12019-01-29
CVE-2019-7150 [MEDIUM] CWE-125 CVE-2019-7150: An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlat
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.
nvd
CVE-2020-12769P4MEDIUMCVSS 5.5v15.1v15.22020-05-09
CVE-2020-12769 [MEDIUM] CWE-662 CVE-2020-12769: An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to
An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.
nvd
CVE-2020-14323P4MEDIUMCVSS 5.5v15.1v15.22020-10-29
CVE-2020-14323 [MEDIUM] CWE-170 CVE-2020-14323: A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, bef
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
nvd
CVE-2018-7858P4MEDIUMCVSS 5.5v42.32018-03-12
CVE-2018-7858 [MEDIUM] CWE-125 CVE-2018-7858: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local g
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
nvd
CVE-2018-18849P4MEDIUMCVSS 5.5v15.0v42.32019-03-21
CVE-2018-18849 [MEDIUM] CWE-125 CVE-2018-18849: In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an inv
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
nvd
CVE-2020-12771P4MEDIUMCVSS 5.5v15.1v15.22020-05-09
CVE-2020-12771 [MEDIUM] CWE-667 CVE-2020-12771: An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/b
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
nvd
CVE-2020-25596P4MEDIUMCVSS 5.5v15.22020-09-23
CVE-2020-25596 [MEDIUM] CWE-74 CVE-2020-25596: An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. This causes the guest kernel to observe a kernel-priv
nvd
CVE-2018-20126P4MEDIUMCVSS 5.5v15.0v15.12018-12-20
CVE-2018-20126 [MEDIUM] CWE-772 CVE-2018-20126: hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mish
hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
nvd
CVE-2020-11669P4MEDIUMCVSS 5.5v15.12020-04-10
CVE-2020-11669 [MEDIUM] CVE-2020-11669: An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/
An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMOR, aka CID-53a712bae5dd.
nvd
CVE-2019-2877P4MEDIUMCVSS 5.5v15.0v15.12019-07-23
CVE-2019-2877 [MEDIUM] CVE-2019-2877: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful atta
nvd
CVE-2020-15305P4MEDIUMCVSS 5.5v15.1v15.22020-06-26
CVE-2020-15305 [MEDIUM] CWE-416 CVE-2020-15305: An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepS
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
nvd
CVE-2020-25598P4MEDIUMCVSS 5.5v15.22020-09-23
CVE-2020-25598 [MEDIUM] CWE-670 CVE-2020-25598: An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource erro
An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path in the XENMEM_acquire_resource exits without releasing an RCU reference, which is conceptually similar to forgetting to unlock a spinlock. A buggy or mal
nvd
CVE-2020-27673P4MEDIUMCVSS 5.5v15.1v15.22020-10-22
CVE-2020-27673 [MEDIUM] CVE-2020-27673: An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.
nvd