Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 85 of 95
CVE-2020-11494P4MEDIUMCVSS 4.4v15.12020-04-02
CVE-2020-11494 [MEDIUM] CWE-908 CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.
An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.
nvd
CVE-2020-10732P4MEDIUMCVSS 4.4v15.1v15.22020-06-12
CVE-2020-10732 [MEDIUM] CWE-908 CVE-2020-10732: A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an a
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
nvd
CVE-2020-15192P4MEDIUMCVSS 4.3v15.22020-09-25
CVE-2020-15192 [MEDIUM] CWE-20 CVE-2020-15192: In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpa
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not properly checked. Since each of the above methods can return an error status, the `status` value must
nvd
CVE-2019-5838P4MEDIUMCVSS 4.3v15.0v15.1+1 more2019-06-27
CVE-2019-5838 [MEDIUM] CWE-863 CVE-2019-5838: Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
nvd
CVE-2019-10740P4MEDIUMCVSS 4.3v15.1v15.22019-04-07
CVE-2019-10740 [MEDIUM] CWE-319 CVE-2019-10740: In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver repl
nvd
CVE-2022-31252P4MEDIUMCVSS 4.4v15.3v15.42022-10-06
CVE-2022-31252 [MEDIUM] CWE-863 CVE-2022-31252: A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged binary to influence path resolutio
nvd
CVE-2018-19841P4MEDIUMCVSS 5.5v15.02018-12-04
CVE-2018-19841 [MEDIUM] CWE-125 CVE-2018-19841: The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allow
The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.
nvd
CVE-2015-8872P4MEDIUMCVSS 6.2v42.12016-06-03
CVE-2015-8872 [MEDIUM] CWE-189 CVE-2015-8872: The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 file
The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."
nvd
CVE-2019-15144P4MEDIUMCVSS 5.5v15.0v15.12019-08-18
CVE-2019-15144 [MEDIUM] CWE-674 CVE-2019-15144: In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.
nvd
CVE-2016-7466P4MEDIUMCVSS 6.0v42.22016-12-10
CVE-2016-7466 [MEDIUM] CWE-772 CVE-2016-7466: Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when th
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.
nvd
CVE-2016-7995P4MEDIUMCVSS 6.0v42.22016-12-10
CVE-2016-7995 [MEDIUM] CWE-772 CVE-2016-7995: Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allow
Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.
nvd
CVE-2016-9106P4MEDIUMCVSS 6.0v42.22016-12-09
CVE-2016-9106 [MEDIUM] CWE-772 CVE-2016-9106: Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local gue
Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.
nvd
CVE-2016-9101P4MEDIUMCVSS 6.0v42.22016-12-09
CVE-2016-9101 [MEDIUM] CWE-772 CVE-2016-9101: Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators t
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
nvd
CVE-2016-8577P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8577 [MEDIUM] CWE-772 CVE-2016-8577: Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local gues
Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.
nvd
CVE-2016-8668P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8668 [MEDIUM] CWE-120 CVE-2016-8668: The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local gu
The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
nvd
CVE-2020-11864P4MEDIUMCVSS 5.5v15.12020-05-11
CVE-2020-11864 [MEDIUM] CVE-2020-11864: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).
nvd
CVE-2019-20053P4MEDIUMCVSS 5.5v15.12019-12-27
CVE-2019-20053 [MEDIUM] CWE-119 CVE-2019-20053: An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
nvd
CVE-2016-0651P4MEDIUMCVSS 5.5v42.12016-04-21
CVE-2016-0651 [MEDIUM] CVE-2016-0651: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors related to Optimizer.
nvd
CVE-2019-19051P4MEDIUMCVSS 5.5v15.12019-11-18
CVE-2019-19051 [MEDIUM] CWE-401 CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c i
A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7.
nvd
CVE-2020-12867P4MEDIUMCVSS 5.5v15.1v15.22020-06-01
CVE-2020-12867 [MEDIUM] CWE-476 CVE-2020-12867: A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
nvd