Opensuse
Opensuse Leap: vulnerabilidades y CVE
Opensuse Leap tiene 1898 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 196 son críticas y 19 figuran en el catálogo de explotación activa de CISA.
CVE1898
Últimos 12 meses1
Críticas196
Explotadas activamente19
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2019-5418 | Alta (7.5) | 99% | ⚠ Explotación activa | 27 mar 2019 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's… |
| CVE-2016-3714 | Alta (8.4) | 97% | ⚠ Explotación activa | 5 may 2016 | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell… |
| CVE-2020-12641 | Crítica (9.8) | 84% | ⚠ Explotación activa | 4 may 2020 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. |
| CVE-2016-3427 | Crítica (9.8) | 92% | ⚠ Explotación activa | 21 abr 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
| CVE-2016-1646 | Alta (8.8) | 48% | ⚠ Explotación activa | 29 mar 2016 | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of… |
| CVE-2019-13720 | Alta (8.8) | 49% | ⚠ Explotación activa | 25 nov 2019 | Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2016-0752 | Alta (7.5) | 96% | ⚠ Explotación activa | 16 feb 2016 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by… |
| CVE-2015-4902 | Media (5.3) | 14% | ⚠ Explotación activa | 22 oct 2015 | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment. |
| CVE-2020-1938 | Crítica (9.8) | 99% | ⚠ Explotación activa | 24 feb 2020 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If… |
| CVE-2016-3715 | Media (5.5) | 75% | ⚠ Explotación activa | 5 may 2016 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
| CVE-2019-0211 | Alta (7.8) | 65% | ⚠ Explotación activa | 8 abr 2019 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter)… |
| CVE-2020-11652 | Media (6.5) | 86% | ⚠ Explotación activa | 30 abr 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary… |
| CVE-2020-11651 | Crítica (9.8) | 97% | ⚠ Explotación activa | 30 abr 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods… |
| CVE-2020-1472 | Crítica (10) | 99% | ⚠ Explotación activa | 17 ago 2020 | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who… |
| CVE-2020-16846 | Crítica (9.8) | 100% | ⚠ Explotación activa | 6 nov 2020 | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. |
| CVE-2020-16009 | Alta (8.8) | 48% | ⚠ Explotación activa | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2016-3718 | Media (5.5) | 77% | ⚠ Explotación activa | 5 may 2016 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2023-32182 | Alta (7.8) | 0.30% | — | 19 sept 2023 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE… |
| CVE-2022-45153 | Alta (7.8) | 0.22% | — | 15 feb 2023 | An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local… |
| CVE-2022-31252 | Media (4.4) | 0.14% | — | 6 oct 2022 | A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local… |
| CVE-2021-46142 | Media (5.5) | 1.1% | — | 6 ene 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. |
| CVE-2021-46141 | Media (5.5) | 1.1% | — | 6 ene 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. |
| CVE-2021-41819 | Alta (7.5) | 2.9% | — | 1 ene 2022 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. |
| CVE-2021-41817 | Alta (7.5) | 3.2% | — | 1 ene 2022 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
| CVE-2021-26676 | Media (6.5) | 1.2% | — | 9 feb 2021 | gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp. |
| CVE-2021-26675 | Alta (8.8) | 1.3% | — | 9 feb 2021 | A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code. |
| CVE-2020-0569 | Media (5.7) | 0.56% | — | 23 nov 2020 | Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. |
| CVE-2020-16846 | Crítica (9.8) | 100% | ⚠ Explotación activa | 6 nov 2020 | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. |
| CVE-2020-28049 | Media (6.3) | 0.42% | — | 4 nov 2020 | An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper… |
| CVE-2020-16011 | Crítica (9.6) | 2.4% | — | 3 nov 2020 | Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
| CVE-2020-16009 | Alta (8.8) | 48% | ⚠ Explotación activa | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16008 | Alta (8.8) | 1.2% | — | 3 nov 2020 | Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet. |
| CVE-2020-16007 | Alta (7.8) | 0.27% | — | 3 nov 2020 | Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem. |
| CVE-2020-16006 | Alta (8.8) | 1.7% | — | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16005 | Alta (8.8) | 1.7% | — | 3 nov 2020 | Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-16004 | Alta (8.8) | 1.5% | — | 3 nov 2020 | Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-14323 | Media (5.5) | 0.62% | — | 29 oct 2020 | A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service. |
| CVE-2020-27673 | Media (5.5) | 0.41% | — | 22 oct 2020 | An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271. |
| CVE-2020-27672 | Alta (7) | 0.26% | — | 22 oct 2020 | An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a… |
| CVE-2020-27671 | Alta (7.8) | 0.34% | — | 22 oct 2020 | An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU… |
| CVE-2020-27670 | Alta (7.8) | 0.25% | — | 22 oct 2020 | An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be… |
| CVE-2020-15683 | Crítica (9.8) | 2.7% | — | 22 oct 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of… |
| CVE-2020-27560 | Baja (3.3) | 1.5% | — | 22 oct 2020 | ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service. |
| CVE-2020-14803 | Media (5.3) | 3.2% | — | 21 oct 2020 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with… |
| CVE-2020-14798 | Baja (3.1) | 2.7% | — | 21 oct 2020 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.