← Back

Leap

leap

Vendor: Opensuse • 1,898 CVEs

CVEs (1,898)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Opensuse
Schismtracker
3Backports
LeapSchism Tracker
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
2Opencv
Opensuse
2Leap
Opencv
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial...Show more
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.Show less
3Debian
Icedtea Web ProjectOpensuse
3Debian Linux
Icedtea WebLeap
Nov 21, 2024
Jul 31, 2019
N/A· v4
8.6 HIGH· v3
6.4 MEDIUM· v2
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This coul...Show more
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.Show less
3Debian
Icedtea Web ProjectOpensuse
3Debian Linux
Icedtea WebLeap
Nov 21, 2024
Jul 31, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a tr...Show more
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Nov 21, 2024
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a...Show more
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Nov 21, 2024
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer...Show more
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Nov 21, 2024
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can displ...Show more
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Libsdl
Opensuse
3Backports Sle
LeapSdl2 Image
Nov 21, 2024
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can displ...Show more
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.Show less
2Opensuse
Powerdns
3Authoritative
BackportsLeap
Nov 21, 2024
Jul 30, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by s...Show more
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.Show less
2Opensuse
Powerdns
2Authoritative
Leap
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their contro...Show more
A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.Show less
2Libpod Project
Opensuse
2Leap
Libpod
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.2 HIGH· v3
2.6 LOW· v2
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the h...Show more
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.Show less
2Opensuse
Videolan
3Backports
LeapVlc Media Player
Nov 21, 2024
Jul 30, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Double Free in VLC versions <= 3.0.6 leads to a crash.
2Opensuse
Videolan
4Backports
Backports SleLeap+1 more
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
2Openmpt
Opensuse
2Leap
Libopenmpt
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
2Openmpt
Opensuse
2Leap
Libopenmpt
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
libopenmpt before 0.3.13 allows a crash with malformed MED files.
2Opensuse
Postgresql
2Leap
Postgresql
Nov 21, 2024
Jul 30, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Cert...Show more
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker.Show less
4Canonical
GnuNetapp+1 more
5Binutils
Hci Management NodeLeap+2 more
Nov 21, 2024
Jul 30, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrate...Show more
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.Show less
3Debian
DockerOpensuse
3Debian Linux
DockerLeap
Nov 21, 2024
Jul 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
7Apple
CanonicalDebian+4 more
9Blockchain Platform
Debian LinuxLeap+6 more
Nov 21, 2024
Jul 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would o...Show more
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections. Depending on the ACL configuration, this can affect different types of operations (searches, modifications, etc.). In other words, a successful authorization step completed by one user affects the authorization requirement for a different user.Show less
7Apple
CanonicalDebian+4 more
9Blockchain Platform
Debian LinuxLeap+6 more
Nov 21, 2024
Jul 26, 2019
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant de...Show more
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)Show less