Vulnerabilities > Opensuse > Leap

DATE CVE VULNERABILITY TITLE RISK
2019-09-11 CVE-2019-16231 NULL Pointer Dereference vulnerability in multiple products
drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
local
high complexity
linux redhat canonical opensuse CWE-476
4.1
2019-09-09 CVE-2019-16167 Integer Overflow or Wraparound vulnerability in multiple products
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
5.5
2019-09-08 CVE-2016-10937 Improper Certificate Validation vulnerability in multiple products
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
7.5
2019-09-06 CVE-2019-9458 Use After Free vulnerability in multiple products
In the Android kernel in the video driver there is a use after free due to a race condition.
local
high complexity
google opensuse CWE-416
7.0
2019-09-06 CVE-2019-9456 Out-of-bounds Write vulnerability in multiple products
In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check.
local
low complexity
google opensuse CWE-787
6.7
2019-09-06 CVE-2019-9455 Reachable Assertion vulnerability in multiple products
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement.
local
low complexity
google opensuse CWE-617
2.3
2019-09-06 CVE-2019-9855 Channel and Path Errors vulnerability in multiple products
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from.
network
low complexity
libreoffice opensuse CWE-417
critical
9.8
2019-09-06 CVE-2019-9854 Path Traversal vulnerability in multiple products
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc.
7.8
2019-09-06 CVE-2019-16056 An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. 7.5
2019-09-06 CVE-2019-14813 Incorrect Authorization vulnerability in multiple products
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions.
network
low complexity
artifex redhat fedoraproject opensuse debian CWE-863
critical
9.8