Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 86 of 95
CVE-2019-19462P4MEDIUMCVSS 5.5v15.1v15.22019-11-30
CVE-2019-19462 [MEDIUM] CWE-476 CVE-2019-19462: relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial
relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
nvd
CVE-2019-20810P4MEDIUMCVSS 5.5v15.1v15.22020-06-03
CVE-2019-20810 [MEDIUM] CWE-401 CVE-2019-20810: go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not cal
go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.
nvd
CVE-2020-15393P4MEDIUMCVSS 5.5v15.1v15.22020-06-29
CVE-2020-15393 [MEDIUM] CWE-401 CVE-2020-15393: In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
nvd
CVE-2020-15304P4MEDIUMCVSS 5.5v15.1v15.22020-06-26
CVE-2020-15304 [MEDIUM] CWE-476 CVE-2020-15304: An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid mem
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
nvd
CVE-2016-0595P4MEDIUMCVSS 4.0v42.12016-01-21
CVE-2016-0595 [MEDIUM] CVE-2016-0595: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2019-9495P4LOWCVSS 3.7v15.12019-04-17
CVE-2019-9495 [LOW] CWE-524 CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache.
nvd
CVE-2020-14573P4LOWCVSS 3.7v15.1v15.22020-07-15
CVE-2020-14573 [LOW] CVE-2020-14573: Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that
Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2016-0606P4LOWCVSS 3.5v42.12016-01-21
CVE-2016-0606 [LOW] CVE-2016-0606: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.
nvd
CVE-2015-4913P4LOWCVSS 3.5v42.12015-10-22
CVE-2015-4913 [LOW] CVE-2015-4913: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
nvd
CVE-2019-15220P4MEDIUMCVSS 4.6v15.0v15.12019-08-19
CVE-2019-15220 [MEDIUM] CWE-416 CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a mali
An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver.
nvd
CVE-2019-15211P4MEDIUMCVSS 4.6v15.0v15.12019-08-19
CVE-2019-15211 [MEDIUM] CWE-416 CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a mali
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.
nvd
CVE-2020-6438P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6438 [MEDIUM] CWE-209 CVE-2020-6438: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an atta
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
nvd
CVE-2020-15959P4MEDIUMCVSS 4.3v15.1v15.22020-09-21
CVE-2020-15959 [MEDIUM] CVE-2020-15959: Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an att
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
nvd
CVE-2020-12864P4MEDIUMCVSS 4.3v15.1v15.22020-06-24
CVE-2020-12864 [MEDIUM] CWE-125 CVE-2020-12864: An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the s
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
nvd
CVE-2020-6570P4MEDIUMCVSS 4.3v15.1v15.22020-09-21
CVE-2020-6570 [MEDIUM] CWE-200 CVE-2020-6570: Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to ob
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.
nvd
CVE-2020-6440P4MEDIUMCVSS 4.3v15.12020-04-13
CVE-2020-6440 [MEDIUM] CVE-2020-6440: Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacke
Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
nvd
CVE-2019-15031P4MEDIUMCVSS 4.4v15.0v15.12019-09-13
CVE-2019-15031 [MEDIUM] CWE-662 CVE-2019-15031: In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers o
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector registers will be corrup
nvd
CVE-2019-5068P4MEDIUMCVSS 4.4v15.12019-11-05
CVE-2019-5068 [MEDIUM] CWE-277 CVE-2019-5068: An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Gr
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
nvd
CVE-2020-15095P4MEDIUMCVSS 4.4v15.1v15.22020-07-07
CVE-2020-15095 [MEDIUM] CWE-532 CVE-2020-15095: Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability thro
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and also to any generated log files.
nvd
CVE-2020-17489P4MEDIUMCVSS 4.3v15.22020-08-11
CVE-2020-17489 [MEDIUM] CWE-522 CVE-2020-17489: An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password we
nvd