cbcvebase.

Opensuse Leap vulnerabilities

1,897 known vulnerabilities affecting opensuse/leap.

Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93

Vulnerabilities

Page 84 of 95
CVE-2015-2697P4MEDIUMCVSS 4.0v42.12015-11-09
CVE-2015-2697 [MEDIUM] CWE-125 CVE-2015-2697: The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
nvd
CVE-2019-18388P4MEDIUMCVSS 5.5v15.12019-12-23
CVE-2019-18388 [MEDIUM] CWE-476 CVE-2019-18388: A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
nvd
CVE-2019-2938P4MEDIUMCVSS 4.4v15.12019-10-16
CVE-2019-2938 [MEDIUM] CVE-2019-2938: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2019-2614P4MEDIUMCVSS 4.4v15.0v15.12019-04-23
CVE-2019-2614 [MEDIUM] CVE-2019-2614: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this v
nvd
CVE-2019-17594P4MEDIUMCVSS 5.3v15.0v15.12019-10-14
CVE-2019-17594 [MEDIUM] CWE-125 CVE-2019-17594: There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the te There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
nvd
CVE-2020-12888P4MEDIUMCVSS 5.3v15.1v15.22020-05-15
CVE-2020-12888 [MEDIUM] CWE-755 CVE-2020-12888: The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
nvd
CVE-2016-0594P4MEDIUMCVSS 4.3v42.12016-01-21
CVE-2016-0594 [MEDIUM] CVE-2016-0594: Unspecified vulnerability in Oracle MySQL 5.6.21 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.6.21 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2016-5746P4MEDIUMCVSS 5.1v42.12016-09-26
CVE-2016-5746 [MEDIUM] CVE-2016-5746: libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devic libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-XXXXXX/pwdf.
nvd
CVE-2016-0611P4MEDIUMCVSS 4.0v42.12016-01-21
CVE-2016-0611 [MEDIUM] CWE-284 CVE-2016-0611: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2020-14712P4MEDIUMCVSS 5.0v15.1v15.22020-07-15
CVE-2020-14712 [MEDIUM] CVE-2020-14712: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. S
nvd
CVE-2016-0503P4MEDIUMCVSS 4.0v42.12016-01-21
CVE-2016-0503 [MEDIUM] CVE-2016-0503: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0504.
nvd
CVE-2020-6489P4MEDIUMCVSS 4.3v15.12020-05-21
CVE-2020-6489 [MEDIUM] CWE-200 CVE-2020-6489: Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a rem Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2020-6531P4MEDIUMCVSS 4.3v15.1v15.22020-07-22
CVE-2020-6531 [MEDIUM] CWE-203 CVE-2020-6531: Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2016-1657P4MEDIUMCVSS 4.3v42.12016-04-18
CVE-2016-1657 [MEDIUM] CWE-254 CVE-2016-1657: The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
nvd
CVE-2016-1658P4MEDIUMCVSS 4.3v42.12016-04-18
CVE-2016-1658 [MEDIUM] CWE-200 CVE-2016-1658: The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
nvd
CVE-2020-15966P4MEDIUMCVSS 4.3v15.1v15.22020-09-21
CVE-2020-15966 [MEDIUM] CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an att Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
nvd
CVE-2020-6571P4MEDIUMCVSS 4.3v15.1v15.22020-09-21
CVE-2020-6571 [MEDIUM] CWE-20 CVE-2020-6571: Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote atta Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2020-6529P4MEDIUMCVSS 4.3v15.1v15.22020-07-22
CVE-2020-6529 [MEDIUM] CWE-295 CVE-2020-6529: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
nvd
CVE-2016-5163P4MEDIUMCVSS 4.3v42.12016-09-11
CVE-2016-5163 [MEDIUM] CWE-254 CVE-2016-5163: The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and b The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar via crafted right-to-left (RTL) Unicode text, related to omnibox/SuggestionView.java and omnibox/UrlBar.java in Chr
nvd
CVE-2019-10163P4MEDIUMCVSS 4.3v15.0v15.12019-07-30
CVE-2019-10163 [MEDIUM] CWE-770 CVE-2019-10163: A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowin A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.
nvd
Opensuse Leap vulnerabilities | cvebase