Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 87 of 95
CVE-2019-12976P4MEDIUMCVSS 5.5v15.0v15.12019-06-26
CVE-2019-12976 [MEDIUM] CWE-401 CVE-2019-12976: ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.
ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.
nvd
CVE-2019-12975P4MEDIUMCVSS 5.5v15.0v15.12019-06-26
CVE-2019-12975 [MEDIUM] CWE-401 CVE-2019-12975: ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.
ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.
nvd
CVE-2016-10068P4MEDIUMCVSS 5.5v42.22017-03-02
CVE-2016-10068 [MEDIUM] CWE-20 CVE-2016-10068: The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of servi
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.
nvd
CVE-2016-8909P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8909 [MEDIUM] CWE-835 CVE-2016-8909: The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.
nvd
CVE-2016-8578P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8578 [MEDIUM] CVE-2016-8578: The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local
The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation.
nvd
CVE-2016-8667P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8667 [MEDIUM] CWE-369 CVE-2016-8667: The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS admi
The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value.
nvd
CVE-2016-9105P4MEDIUMCVSS 6.0v42.22016-12-09
CVE-2016-9105 [MEDIUM] CWE-772 CVE-2016-9105: Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local gues
Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.
nvd
CVE-2016-7422P4MEDIUMCVSS 6.0v42.22016-12-10
CVE-2016-7422 [MEDIUM] CWE-120 CVE-2016-7422: The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local gues
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
nvd
CVE-2016-8669P4MEDIUMCVSS 6.0v42.22016-11-04
CVE-2016-8669 [MEDIUM] CWE-369 CVE-2016-8669: The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base.
nvd
CVE-2020-11863P4MEDIUMCVSS 5.5v15.12020-05-11
CVE-2020-11863 [MEDIUM] CVE-2020-11863: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
nvd
CVE-2020-12767P4MEDIUMCVSS 5.5v15.12020-05-09
CVE-2020-12767 [MEDIUM] CWE-369 CVE-2020-12767: exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
nvd
CVE-2020-8992P4MEDIUMCVSS 5.5v15.12020-02-14
CVE-2020-8992 [MEDIUM] CWE-400 CVE-2020-8992: ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows att
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
nvd
CVE-2019-20095P4MEDIUMCVSS 5.5v15.12019-12-30
CVE-2019-20095 [MEDIUM] CWE-401 CVE-2019-20095: mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 h
mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID-003b686ace82. This will cause a memory leak and denial of service.
nvd
CVE-2019-19077P4MEDIUMCVSS 5.5v15.12019-11-18
CVE-2019-19077 [MEDIUM] CWE-401 CVE-2019-19077: A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in th
A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14.
nvd
CVE-2020-2756P4LOWCVSS 3.7v15.1v15.22020-04-15
CVE-2020-2756 [LOW] CWE-502 CVE-2020-2756: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization).
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2020-2757P4LOWCVSS 3.7v15.1v15.22020-04-15
CVE-2020-2757 [LOW] CWE-502 CVE-2020-2757: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization).
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2020-14707P4MEDIUMCVSS 5.0v15.1v15.22020-07-15
CVE-2020-14707 [MEDIUM] CVE-2020-14707: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. S
nvd
CVE-2016-1955P4MEDIUMCVSS 4.3v42.12016-03-13
CVE-2016-1955 [MEDIUM] CWE-200 CVE-2016-1955: Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sens
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
nvd
CVE-2019-15666P4MEDIUMCVSS 4.4v15.0v15.12019-08-27
CVE-2019-15666 [MEDIUM] CWE-125 CVE-2019-15666: An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in
An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.
nvd
CVE-2020-14577P4LOWCVSS 3.7v15.1v15.22020-07-15
CVE-2020-14577 [LOW] CVE-2020-14577: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this
nvd