Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 83 of 95
CVE-2018-19840P4MEDIUMCVSS 5.5v15.02018-12-04
CVE-2018-19840 [MEDIUM] CWE-835 CVE-2018-19840: The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attacke
The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.
nvd
CVE-2016-2042P4MEDIUMCVSS 5.3v42.12016-02-20
CVE-2016-2042 [MEDIUM] CWE-200 CVE-2016-2042: phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
nvd
CVE-2014-9853P4MEDIUMCVSS 5.5v42.12017-03-17
CVE-2014-9853 [MEDIUM] CWE-399 CVE-2014-9853: Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (mem
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
nvd
CVE-2016-8910P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8910 [MEDIUM] CWE-835 CVE-2016-8910: The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local gu
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
nvd
CVE-2016-8576P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8576 [MEDIUM] CWE-770 CVE-2016-8576: The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.
nvd
CVE-2016-6265P4MEDIUMCVSS 5.5v42.12016-09-22
CVE-2016-6265 [MEDIUM] CWE-416 CVE-2016-6265: Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
nvd
CVE-2019-15145P4MEDIUMCVSS 5.5v15.0v15.12019-08-18
CVE-2019-15145 [MEDIUM] CWE-125 CVE-2019-15145: DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in libdjvu/GBitmap.h.
nvd
CVE-2020-12866P4MEDIUMCVSS 5.7v15.1v15.22020-06-24
CVE-2020-12866 [MEDIUM] CWE-476 CVE-2020-12866: A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
nvd
CVE-2019-14444P4MEDIUMCVSS 5.5v15.1v15.22019-07-30
CVE-2019-14444 [MEDIUM] CWE-190 CVE-2019-14444: apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attacke
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
nvd
CVE-2018-19872P4MEDIUMCVSS 5.5v15.02019-03-21
CVE-2018-19872 [MEDIUM] CWE-369 CVE-2018-19872: An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in q
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
nvd
CVE-2019-7665P4MEDIUMCVSS 5.5v15.0v15.12019-02-09
CVE-2019-7665 [MEDIUM] CWE-125 CVE-2019-7665: In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in el
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.
nvd
CVE-2015-7208P4MEDIUMCVSS 5.0v42.12015-12-16
CVE-2015-7208 [MEDIUM] CWE-200 CVE-2015-7208: Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote a
Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.
nvd
CVE-2021-46141P4MEDIUMCVSS 5.5v15.32022-01-06
CVE-2021-46141 [MEDIUM] CWE-416 CVE-2021-46141: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUri
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
nvd
CVE-2021-46142P4MEDIUMCVSS 5.5v15.32022-01-06
CVE-2021-46142 [MEDIUM] CWE-416 CVE-2021-46142: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormali
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
nvd
CVE-2020-0569P4MEDIUMCVSS 5.7v15.12020-11-23
CVE-2020-0569 [MEDIUM] CWE-787 CVE-2020-0569: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticat
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
nvd
CVE-2019-3886P4MEDIUMCVSS 5.4v42.32019-04-04
CVE-2019-3886 [MEDIUM] CWE-862 CVE-2019-3886: An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission wa
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
nvd
CVE-2020-14392P4MEDIUMCVSS 5.5v15.1v15.22020-09-16
CVE-2020-14392 [MEDIUM] CWE-822 CVE-2020-14392: An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
nvd
CVE-2018-19364P4MEDIUMCVSS 5.5v42.32018-12-13
CVE-2018-19364 [MEDIUM] CWE-416 CVE-2018-19364: hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a sec
hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
nvd
CVE-2020-10769P4MEDIUMCVSS 5.5v15.12020-06-26
CVE-2020-10769 [MEDIUM] CWE-125 CVE-2020-10769: A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in
A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than 4 bytes, and is not following 4-byte alignment boundary guidelines, it causes a buffer over-read threat, leading to a system crash. This flaw allows a l
nvd
CVE-2018-16878P4MEDIUMCVSS 5.5v15.0v42.32019-04-18
CVE-2018-16878 [MEDIUM] CWE-400 CVE-2018-16878: A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflic
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
nvd