← Back

Leap

leap

Vendor: Opensuse • 1,898 CVEs

CVEs (1,898)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Opensuse
2Chrome
Leap
May 6, 2026
Sep 11, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unsp...Show more
Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JBig2 image.Show less
2Google
Opensuse
2Chrome
Leap
May 6, 2026
Sep 11, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a...Show more
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-destruction) or possibly have unspecified other impact via a crafted web site.Show less
2Google
Opensuse
2Chrome
Leap
May 6, 2026
Sep 11, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to...Show more
Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.Show less
2Google
Opensuse
2Chrome
Leap
May 6, 2026
Sep 11, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified...Show more
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PDF document, related to fpdfsdk/javascript/JS_Object.cpp and fpdfsdk/javascript/app.cpp.Show less
2Google
Opensuse
2Chrome
Leap
May 6, 2026
Sep 11, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implement...Show more
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code that leverages certain side effects.Show less
2Google
Opensuse
2Chrome
Leap
May 6, 2026
Sep 11, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to cond...Show more
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injection attacks by leveraging script access to a resource that initially has the about:blank URL.Show less
3Canonical
GnuOpensuse
4Leap
LibidnOpensuse+1 more
May 6, 2026
Sep 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
3Canonical
GnuOpensuse
3Leap
LibidnUbuntu Linux
May 6, 2026
Sep 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
3Canonical
GnuOpensuse
4Leap
LibidnOpensuse+1 more
May 6, 2026
Sep 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
3Cracklib Project
DebianOpensuse
3Cracklib
Debian LinuxLeap
May 6, 2026
Sep 7, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffe...Show more
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.Show less
4Canonical
FedoraprojectGnome+1 more
5Eye Of Gnome
FedoraLeap+2 more
May 6, 2026
Sep 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via ve...Show more
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.Show less
2Opensuse
Roundcube
2Leap
Webmail
May 6, 2026
Aug 25, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk c...Show more
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.Show less
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
4Debian
LibgdOpensuse+1 more
4Debian Linux
LeapLibgd+1 more
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory cons...Show more
Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.Show less
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
3Debian
LibgdOpensuse
3Debian Linux
LeapLibgd
May 6, 2026
Aug 12, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
5Canonical
DebianFedoraproject+2 more
6Debian Linux
FedoraLeap+3 more
May 6, 2026
Aug 10, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
3Debian
HaxxOpensuse
3Debian Linux
LeapLibcurl
May 6, 2026
Aug 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously c...Show more
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.Show less
3Debian
HaxxOpensuse
3Debian Linux
LeapLibcurl
May 6, 2026
Aug 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
4Canonical
DebianLibgd+1 more
4Debian Linux
LeapLibgd+1 more
May 6, 2026
Aug 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid col...Show more
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.Show less