Vulnerabilities > Opensuse > Leap > High

DATE CVE VULNERABILITY TITLE RISK
2019-07-23 CVE-2019-2865 Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).
local
high complexity
oracle opensuse
7.5
2019-07-23 CVE-2019-2864 Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).
local
high complexity
oracle opensuse
7.5
2019-07-23 CVE-2019-2859 Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).
local
low complexity
oracle opensuse
8.8
2019-07-23 CVE-2019-9811 Injection vulnerability in multiple products
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation.
network
high complexity
mozilla debian novell opensuse CWE-74
8.3
2019-07-23 CVE-2019-11723 Origin Validation Error vulnerability in multiple products
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context.
network
low complexity
mozilla opensuse CWE-346
7.5
2019-07-17 CVE-2019-13619 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash.
7.5
2019-07-16 CVE-2019-13616 Out-of-bounds Read vulnerability in multiple products
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
8.1
2019-07-15 CVE-2019-1010006 Integer Overflow or Wraparound vulnerability in multiple products
Evince 3.26.0 is affected by buffer overflow.
local
low complexity
gnome canonical debian opensuse CWE-190
7.8
2019-07-14 CVE-2019-13602 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
local
low complexity
videolan debian canonical opensuse CWE-191
7.8
2019-07-05 CVE-2019-13308 Out-of-bounds Write vulnerability in multiple products
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.
network
low complexity
imagemagick canonical debian opensuse CWE-787
8.8