Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Ubuntu Linux MEDIUM 6.5
CVE-2017-14342

ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.

No fix yet
Fix from $1,600 2017-09-12
Debian Linux MEDIUM 6.5
CVE-2017-14223

In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumpti…

Patch available
Fix from $1,600 2017-09-09
Googlemaps HIGH 7.5
CVE-2013-7428

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.ph…

Fix: after 3.0
Fix from $1,950 2017-09-07
Scrapy HIGH 7.5
CVE-2017-14158

Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into mem…

No fix yet
Fix from $1,950 2017-09-05
Gedit MEDIUM 5.5
CVE-2017-14108

libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0'…

Fix: after 3.22.1
Fix from $1,600 2017-09-05
Imagemagick HIGH 7.5
CVE-2017-14137

ReadWEBPImage in coders/webp.c in ImageMagick 7.0.6-5 has an issue where memory allocation is excessive because it depends only on a length field in …

Patch available
Fix from $1,950 2017-09-04
Designate MEDIUM 6.5
CVE-2015-5695

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when proc…

Patch available
Fix from $1,600 2017-08-31
Android HIGH 7.8
CVE-2017-8264

A userspace process can cause a Denial of Service in the camera driver in all Qualcomm products with Android releases from CAF using the Linux kernel.

Patch available
Fix from $1,950 2017-08-11
Capnproto HIGH 7.5
CVE-2015-2312

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource con…

Fix: after 0.4.1.0
Fix from $1,950 2017-08-09
Capnproto HIGH 7.5
CVE-2015-2313

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote pe…

Fix: after 0.4.1.0
Fix from $1,950 2017-08-09
Imagemagick MEDIUM 6.5
CVE-2017-12140

The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafte…

Patch available
Fix from $1,600 2017-08-02
Soundtouch MEDIUM 5.5
CVE-2017-9259EPSS 6%

The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of se…

No fix yet
Fix from $1,600 2017-07-27
FreeBSD HIGH 7.5
CVE-2015-1417

The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEAS…

Mitigation only
Fix from $1,950 2017-07-25
Imagemagick MEDIUM 6.5
CVE-2017-11526

The ReadOneMNGImage function in coders/png.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of servic…

Fix: after 6.9.8-10
Fix from $1,600 2017-07-23
Imagemagick MEDIUM 6.5
CVE-2017-11527

The ReadDPXImage function in coders/dpx.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (…

Fix: after 6.9.8-10
Fix from $1,600 2017-07-23
Imagemagick MEDIUM 6.5
CVE-2017-11530

The ReadEPTImage function in coders/ept.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (…

Fix: after 6.9.8-10
Fix from $1,600 2017-07-23
Debian Linux HIGH 7.5
CVE-2017-11521

The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of se…

Patch available
Fix from $1,950 2017-07-22
Iphone Os HIGH 7.5
CVE-2017-7063

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. watchOS before 3.2.3 is affected. The issue involves the "Messages"…

Fix: after 10.3.2
Fix from $1,950 2017-07-20
Iphone Os HIGH 7.5
CVE-2017-7007

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "EventKitUI" component. It allows remote att…

Fix: after 10.3.2
Fix from $1,950 2017-07-20
Openmeetings HIGH 7.5
CVE-2017-7684

Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files…

Mitigation only
Fix from $1,950 2017-07-17
Junos HIGH 7.5
CVE-2017-2348

The Juniper Enhanced jdhcpd daemon may experience high CPU utilization, or crash and restart upon receipt of an invalid IPv6 UDP packet. Both high CP…

Mitigation only
Fix from $1,950 2017-07-17
Kitto HIGH 7.5
CVE-2017-1000064

kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS

No fix yet
Fix from $1,950 2017-07-17
Netweaver HIGH 7.5
CVE-2017-9845

disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG reque…

Mitigation only
Fix from $1,950 2017-07-12
Traffic Control HIGH 7.5
CVE-2017-7670

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connec…

Fix: after 1.8.0
Fix from $1,950 2017-07-10
PHP HIGH 7.5
CVE-2017-11142EPSS 8%

In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting…

Fix: after 5.6.30
Fix from $1,950 2017-07-10
Graphicsmagick MEDIUM 5.5
CVE-2017-11140

The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remot…

Patch available
Fix from $1,600 2017-07-10
Wonderware Archestra Logger HIGH 8.6
CVE-2017-9627

An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The …

Mitigation only
Fix from $1,950 2017-07-07
Android MEDIUM 5.5
CVE-2017-0690

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. And…

Mitigation only
Fix from $1,600 2017-07-06
Xen HIGH 7.5
CVE-2017-10922

The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss …

Fix: after 4.8.1
Fix from $1,950 2017-07-05
Graphicsmagick MEDIUM 5.5
CVE-2017-10799

When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in Rea…

Patch available
Fix from $1,600 2017-07-03