cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 82 of 95
CVE-2019-19451P4MEDIUMCVSS 5.5v15.12019-11-29
CVE-2019-19451 [MEDIUM] CWE-835 CVE-2019-19451: When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges
nvd
CVE-2019-5804P4MEDIUMCVSS 5.5v15.0v15.1+1 more2019-05-23
CVE-2019-5804 [MEDIUM] CWE-88 CVE-2019-5804: Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local a Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name.
nvd
CVE-2016-0616P4MEDIUMCVSS 4.0v42.12016-01-21
CVE-2016-0616 [MEDIUM] CVE-2016-0616: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x befor Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-4815P4MEDIUMCVSS 4.0v42.12015-10-21
CVE-2015-4815 [MEDIUM] CVE-2015-4815: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL.
nvd
CVE-2020-15719P4MEDIUMCVSS 4.2v15.1v15.22020-07-14
CVE-2020-15719 [MEDIUM] CWE-295 CVE-2020-15719: libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-pa libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
nvd
CVE-2015-4826P4MEDIUMCVSS 4.0v42.12015-10-21
CVE-2015-4826 [MEDIUM] CVE-2015-4826: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types.
nvd
CVE-2019-11728P4MEDIUMCVSS 4.7v15.0v15.12019-07-23
CVE-2019-11728 [MEDIUM] CWE-668 CVE-2019-11728: The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.
nvd
CVE-2020-14792P4MEDIUMCVSS 4.2v15.22020-10-21
CVE-2020-14792 [MEDIUM] CVE-2020-14792: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Suppo Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
CVE-2016-1943P4MEDIUMCVSS 4.7v42.12016-01-31
CVE-2016-1943 [MEDIUM] CWE-17 CVE-2016-1943: Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scro Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
nvd
CVE-2020-6442P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6442 [MEDIUM] CWE-668 CVE-2020-6442: Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attack Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6432P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6432 [MEDIUM] CVE-2020-6432: Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remo Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6433P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6433 [MEDIUM] CVE-2020-6433: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remot Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6435P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6435 [MEDIUM] CVE-2020-6435: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remot Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6431P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6431 [MEDIUM] CWE-276 CVE-2020-6431: Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remo Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6488P4MEDIUMCVSS 4.3v15.12020-05-21
CVE-2020-6488 [MEDIUM] CWE-276 CVE-2020-6488: Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6528P4MEDIUMCVSS 4.3v15.1v15.22020-07-22
CVE-2020-6528 [MEDIUM] CVE-2020-6528: Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote a Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2016-2832P4MEDIUMCVSS 4.3v42.12016-06-13
CVE-2016-2832 [MEDIUM] CWE-200 CVE-2016-2832: Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a f Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
nvd
CVE-2020-6490P4MEDIUMCVSS 4.3v15.12020-05-21
CVE-2020-6490 [MEDIUM] CWE-668 CVE-2020-6490: Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attac Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6536P4MEDIUMCVSS 4.3v15.1v15.22020-07-22
CVE-2020-6536 [MEDIUM] CVE-2020-6536: Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who h Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
nvd
CVE-2020-1770P4MEDIUMCVSS 4.3v15.1v15.22020-03-27
CVE-2020-1770 [MEDIUM] CWE-201 CVE-2020-1770: Support bundle generated files could contain sensitive information that might be unwanted to be disc Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
nvd
Opensuse Leap vulnerabilities | cvebase