openSUSE / Leap
1,912 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-27673 | kernel: xen: guest OS users can cause a DoS via a high rate of events to dom0 (XSA-332) | MEDIUM | 5.5 | Oct 22, 2020 |
| CVE-2020-15683 | Mozilla: Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4 | CRITICAL | 9.8 | Oct 22, 2020 |
| CVE-2020-27560 | ImageMagick: division by zero in OptimizeLayerFrames function in MagickCore/layer.c | LOW | 3.3 | Oct 22, 2020 |
| CVE-2020-14803 | OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) | MEDIUM | 5.3 | Oct 21, 2020 |
| CVE-2020-14798 | OpenJDK: Missing maximum length check in WindowsNativeDispatcher.asNativeBuffer() (Libraries, 8242695) | LOW | 3.1 | Oct 21, 2020 |
| CVE-2020-14797 | OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) | LOW | 3.7 | Oct 21, 2020 |
| CVE-2020-14796 | OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) | LOW | 3.1 | Oct 21, 2020 |
| CVE-2020-14792 | OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) | MEDIUM | 4.2 | Oct 21, 2020 |
| CVE-2020-14782 | OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) | LOW | 3.7 | Oct 21, 2020 |
| CVE-2020-14781 | OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) | LOW | 3.7 | Oct 21, 2020 |
| CVE-2020-14779 | OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) | LOW | 3.7 | Oct 21, 2020 |
| CVE-2020-25829 | An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a gi… | HIGH | 7.5 | Oct 16, 2020 |
| CVE-2020-27153 | bluez: double free in gatttool client disconnect callback handler in src/shared/att.c could lead to DoS or RCE | HIGH | 8.8 | Oct 15, 2020 |
| CVE-2020-15229 | Path traversal and files overwrite with unsquashfs | CRITICAL | 9.3 | Oct 14, 2020 |
| CVE-2020-25645 | kernel: Geneve/IPsec traffic may be unencrypted between two Geneve endpoints | HIGH | 7.5 | Oct 13, 2020 |
| CVE-2020-26934 | phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. | MEDIUM | 6.1 | Oct 10, 2020 |
| CVE-2020-26935 | An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin pro… | CRITICAL | 9.8 | Oct 10, 2020 |
| CVE-2020-26164 | In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memor… | MEDIUM | 5.5 | Oct 7, 2020 |
| CVE-2020-11800 | Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. | CRITICAL | 9.8 | Oct 7, 2020 |
| CVE-2020-14355 | spice: multiple buffer overflow vulnerabilities in QUIC decoding code | MEDIUM | 6.6 | Oct 7, 2020 |
| CVE-2020-25863 | wireshark: MIME multipart dissector crash (wnpa-sec-2020-11) | HIGH | 7.5 | Oct 6, 2020 |
| CVE-2020-25866 | wireshark: BLIP dissector crash (wnpa-sec-2020-13) | HIGH | 7.5 | Oct 6, 2020 |
| CVE-2020-25862 | wireshark: TCP dissector crash (wnpa-sec-2020-12) | HIGH | 7.5 | Oct 6, 2020 |
| CVE-2020-25641 | kernel: soft-lockups in iov_iter_copy_from_user_atomic() could result in DoS | MEDIUM | 5.5 | Oct 6, 2020 |
| CVE-2020-25643 | kernel: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow | HIGH | 7.2 | Oct 6, 2020 |
Showing 26 to 50 of 1,912 CVEs