Opensuse Leap vulnerabilities
1,897 known vulnerabilities affecting opensuse/leap.
Total CVEs
1,897
CISA KEV
19
actively exploited
Public exploits
59
Exploited in wild
28
Severity breakdown
CRITICAL200HIGH801MEDIUM803LOW93
Vulnerabilities
Page 95 of 95
CVE-2019-11884P4LOWCVSS 3.3v15.0v15.1+1 more2019-05-10
CVE-2019-11884 [LOW] CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allow
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
nvd
CVE-2020-11043P4LOWCVSS 2.7v15.12020-05-29
CVE-2020-11043 [LOW] CWE-125 CVE-2020-11043: In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_process_message_tilese
In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_process_message_tileset. Invalid data fed to RFX decoder results in garbage on screen (as colors). This has been patched in 2.1.0.
nvd
CVE-2020-11040P4LOWCVSS 2.7v15.12020-05-29
CVE-2020-11040 [LOW] CWE-125 CVE-2020-11040: In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_deco
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_decompress_subcode_rlex, visualized on screen as color. This has been patched in 2.1.0.
nvd
CVE-2020-11525P4LOWCVSS 2.2v15.12020-05-15
CVE-2020-11525 [LOW] CWE-125 CVE-2020-11525: libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
nvd
CVE-2020-8013P4LOWCVSS 2.5v15.12020-03-02
CVE-2020-8013 [LOW] CWE-59 CVE-2020-8013: A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12
A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation i
nvd
CVE-2019-2873P4LOWCVSS 3.3v15.0v15.12019-07-23
CVE-2019-2873 [LOW] CVE-2019-2873: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks
nvd
CVE-2019-2875P4LOWCVSS 3.3v15.0v15.12019-07-23
CVE-2019-2875 [LOW] CVE-2019-2875: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks
nvd
CVE-2019-2876P4LOWCVSS 3.3v15.0v15.12019-07-23
CVE-2019-2876 [LOW] CVE-2019-2876: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks
nvd
CVE-2019-2874P4LOWCVSS 3.3v15.0v15.12019-07-23
CVE-2019-2874 [LOW] CVE-2019-2874: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks
nvd
CVE-2016-4983P4LOWCVSS 3.3v42.1v42.22019-11-05
CVE-2016-4983 [LOW] CWE-732 CVE-2016-4983: A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
nvd
CVE-2020-2748P4LOWCVSS 3.2v15.12020-04-15
CVE-2020-2748 [LOW] CWE-125 CVE-2020-2748: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
nvd
CVE-2020-2909P4LOWCVSS 2.8v15.12020-04-15
CVE-2020-2909 [LOW] CVE-2020-2909: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Success
nvd
CVE-2019-2850P4LOWCVSS 2.8v15.0v15.12019-07-23
CVE-2019-2850 [LOW] CVE-2019-2850: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). S
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks
nvd
CVE-2020-13659P4LOWCVSS 2.5v15.22020-06-02
CVE-2020-13659 [LOW] CWE-476 CVE-2020-13659: address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBu
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
nvd
CVE-2019-9455P4LOWCVSS 2.3v15.12019-09-06
CVE-2019-9455 [LOW] CWE-209 CVE-2019-9455: In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement.
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-1000002P4LOWCVSS 2.4v42.22019-11-05
CVE-2016-1000002 [LOW] CWE-200 CVE-2016-1000002: gdm3 3.14.2 and possibly later has an information leak before screen lock
gdm3 3.14.2 and possibly later has an information leak before screen lock
nvd
CVE-2019-20386P4LOWCVSS 2.4v15.12020-01-21
CVE-2019-20386 [LOW] CWE-401 CVE-2019-20386: An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executin
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
nvd
← Previous95 / 95