Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Graphicsmagick MEDIUM 5.5
CVE-2017-10800

When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified…

Patch available
Fix from $1,600 2017-07-03
Bmxnoc0401 Firmware HIGH 7.5
CVE-2017-6017

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP3…

Mitigation only
Fix from $1,950 2017-06-30
Openvpn MEDIUM 5.9
CVE-2017-7521

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double…

Fix: after 2.3.16
Fix from $1,600 2017-06-27
Vtscada HIGH 7.5
CVE-2017-6043

A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit …

Fix: after 11.2.23
Fix from $1,950 2017-06-21
Freeware Advanced Audio Coder MEDIUM 5.5
CVE-2017-9129

The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (lar…

No fix yet
Fix from $1,600 2017-06-21
OpenBSD MEDIUM 6.5
CVE-2017-1000373EPSS 13%

The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort()…

Fix: after 6.1
Fix from $1,600 2017-06-19
Netbsd CRITICAL 9.8
CVE-2017-1000378

The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() …

Fix: after 7.1
Fix from $2,300 2017-06-19
Ws Xmlrpc MEDIUM 6.5
CVE-2016-5004EPSS 6%

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource …

No fix yet
Fix from $1,600 2017-06-06
Mac Os X HIGH 7.8
CVE-2017-2535

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers…

Fix: after 10.12.4
Fix from $1,950 2017-05-22
Firepower Threat Defense HIGH 7.5
CVE-2017-6632

A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could all…

Mitigation only
Fix from $1,950 2017-05-22
PHP CRITICAL 9.8
CVE-2017-9119

The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application …

Patch available
Fix from $2,300 2017-05-21
Mguard Firmware HIGH 7.5
CVE-2017-7935

A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the device's a…

Mitigation only
Fix from $1,950 2017-05-19
Routeros HIGH 7.5
CVE-2017-8338

A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on …

No fix yet
Fix from $1,950 2017-05-18
Simatic Cp 343 1 Std Firmware MEDIUM 6.5
CVE-2017-2681

Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of…

Fix: 2.0 / 2.1.82+
Fix from $1,600 2017-05-11
Simatic Cp 343 1 Std Firmware MEDIUM 6.5
CVE-2017-2680

Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)…

Fix: 2.0 / 2.1.82+
Fix from $1,600 2017-05-11
Compactlogix 5380 Firmware MEDIUM 5.9
CVE-2017-6024

A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 cont…

Mitigation only
Fix from $1,600 2017-05-06
Imageworsener MEDIUM 6.5
CVE-2017-8327

The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of …

Fix: after 1.3.0
Fix from $1,600 2017-04-29
Northstar Controller MEDIUM 5.5
CVE-2017-2322

A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authentica…

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Opendaylight HIGH 7.5
CVE-2017-1000357

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2swi…

No fix yet
Fix from $1,950 2017-04-24
Opendaylight MEDIUM 5.3
CVE-2017-1000359

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version…

No fix yet
Fix from $1,600 2017-04-24
Northstar Controller MEDIUM 5.5
CVE-2017-2327

A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticat…

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Northstar Controller MEDIUM 6.5
CVE-2017-2333

A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a m…

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Imageworsener MEDIUM 5.5
CVE-2017-7940

The iw_read_gif_file function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available …

Patch available
Fix from $1,600 2017-04-18
MongoDB HIGH 7.5
CVE-2016-3104

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termin…

Mitigation only
Fix from $1,950 2017-04-14
Conext Combox 865 1058 Firmware HIGH 7.5
CVE-2017-6019EPSS 37%

An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests …

Fix: after 3.03
Fix from $1,950 2017-04-07
Secure Firewall Management Center MEDIUM 5.9
CVE-2017-3885

A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthent…

Mitigation only
Fix from $1,600 2017-04-07
Backbox Linux HIGH 7.5
CVE-2017-7397EPSS 11%

BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addr…

No fix yet
Fix from $1,950 2017-04-03
Cloudengine 6800 Firmware MEDIUM 6.5
CVE-2016-8780

Huawei CloudEngine 6800 V100R006C00, CloudEngine 7800 V100R006C00, CloudEngine 8800 V100R006C00, and CloudEngine 12800 V100R006C00 allow remote attac…

Mitigation only
Fix from $1,600 2017-04-02
Iphone Os HIGH 7.5
CVE-2017-2461

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch…

Fix: after 10.12.3
Fix from $1,950 2017-04-02
Routeros HIGH 7.5
CVE-2017-7285EPSS 19%

A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all ava…

No fix yet
Fix from $1,950 2017-03-29