openSUSE / Leap
1,912 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-31431 KEV | crypto: algif_aead - Revert to operating out-of-place | HIGH | 7.8 | Apr 22, 2026 |
| CVE-2025-32463 KEV | sudo: LPE via chroot option | CRITICAL | 9.3 | Jun 30, 2025 |
| CVE-2023-32182 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise… | HIGH | 7.8 | Sep 19, 2023 |
| CVE-2022-45153 | saphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.sls | HIGH | 7.8 | Feb 15, 2023 |
| CVE-2022-31252 | permissions: chkstat does not check for group-writable parent directories or target files in safeOpen() | MEDIUM | 4.4 | Oct 6, 2022 |
| CVE-2021-46141 | uriparser: Invalid free operations in uriFreeUriMembers and uriMakeOwner | MEDIUM | 5.5 | Jan 6, 2022 |
| CVE-2021-46142 | uriparser: Invalid free operations in uriNormalizeSyntax. | MEDIUM | 5.5 | Jan 6, 2022 |
| CVE-2021-41819 | ruby: Cookie prefix spoofing in CGI::Cookie.parse | HIGH | 7.5 | Jan 1, 2022 |
| CVE-2021-41817 | ruby: Regular expression denial of service vulnerability of Date parsing methods | HIGH | 7.5 | Jan 1, 2022 |
| CVE-2021-26676 | gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp. | MEDIUM | 6.5 | Feb 9, 2021 |
| CVE-2021-26675 | A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code. | HIGH | 8.8 | Feb 9, 2021 |
| CVE-2020-0569 | qt: files placed by attacker can influence the working directory and lead to malicious code execution | HIGH | 7.3 | Nov 23, 2020 |
| CVE-2020-16846 KEV | salt: sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection | CRITICAL | 9.8 | Nov 6, 2020 |
| CVE-2020-28049 | An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to… | MEDIUM | 6.3 | Nov 4, 2020 |
| CVE-2020-16011 | chromium-browser: Heap buffer overflow in UI on Windows | CRITICAL | 9.6 | Nov 3, 2020 |
| CVE-2020-16009 KEV | chromium-browser: Inappropriate implementation in V8 | HIGH | 8.8 | Nov 3, 2020 |
| CVE-2020-16008 | chromium-browser: Stack buffer overflow in WebRTC | HIGH | 8.8 | Nov 3, 2020 |
| CVE-2020-16007 | chromium-browser: Insufficient data validation in installer | HIGH | 8.8 | Nov 3, 2020 |
| CVE-2020-16006 | chromium-browser: Inappropriate implementation in V8 | HIGH | 8.8 | Nov 3, 2020 |
| CVE-2020-16005 | chromium-browser: Insufficient policy enforcement in ANGLE | HIGH | 8.8 | Nov 3, 2020 |
| CVE-2020-16004 | chromium-browser: Use after free in user interface | HIGH | 8.8 | Nov 3, 2020 |
| CVE-2020-14323 | samba: Unprivileged user can crash winbind | MEDIUM | 5.5 | Oct 29, 2020 |
| CVE-2020-27670 | xen: unsafe AMD IOMMU page table updates (XSA-347) | HIGH | 7.8 | Oct 22, 2020 |
| CVE-2020-27671 | xen: undue deferral of IOMMU TLB flushes (XSA-346) | HIGH | 7.8 | Oct 22, 2020 |
| CVE-2020-27672 | xen: x86: race condition in Xen mapping code (XSA-345) | HIGH | 7.8 | Oct 22, 2020 |
Showing 1 to 25 of 1,912 CVEs