Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Uclibc Ng HIGH 7.5
CVE-2016-2224

The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) …

Fix: after 1.0.11
Fix from $1,950 2017-03-24
Uclibc Ng HIGH 7.5
CVE-2016-2225

The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loo…

Fix: after 1.0.11
Fix from $1,950 2017-03-24
Imagemagick MEDIUM 5.5
CVE-2016-10047

Memory leak in the NewXMLTree function in magick/xml-tree.c in ImageMagick before 6.9.4-7 allows remote attackers to cause a denial of service (memor…

Fix: after 6.9.4-6
Fix from $1,600 2017-03-23
Imagemagick MEDIUM 5.5
CVE-2016-10058

Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick before 6.9.6-3 allows remote attackers to cause a denial of service (memory …

Fix: after 6.9.6-2
Fix from $1,600 2017-03-23
Ios Xe HIGH 7.5
CVE-2017-3856

A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected devic…

Mitigation only
Fix from $1,950 2017-03-22
iOS HIGH 7.5
CVE-2017-3857

A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 through 15.6) and Cisco IOS XE (3.…

Fix: after 15.6
Fix from $1,950 2017-03-22
Ubuntu Linux HIGH 7.5
CVE-2014-9849

The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).

Patch available
Fix from $1,950 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9842

Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consump…

Patch available
Fix from $1,950 2017-03-20
Routeros HIGH 7.5
CVE-2017-6444EPSS 13%

The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows …

No fix yet
Fix from $1,950 2017-03-12
Livebox Firmware HIGH 7.5
CVE-2017-6552

Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled …

No fix yet
Fix from $1,950 2017-03-09
Webkit HIGH 7.5
CVE-2016-9643

The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (op…

Mitigation only
Fix from $1,950 2017-03-07
Owncloud MEDIUM 6.5
CVE-2017-5867

ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of …

Fix: after 8.1.10
Fix from $1,600 2017-03-03
Linux Kernel HIGH 7.5
CVE-2017-5972EPSS 24%

The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which …

Fix: after 3.19.8
Fix from $1,950 2017-02-14
Nport 5100 Series Firmware HIGH 7.5
CVE-2016-9367

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2…

Fix: after 3.10
Fix from $1,950 2017-02-13
Magelis Gtu Universal Panel Firmware MEDIUM 5.3
CVE-2016-8367

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all version…

Mitigation only
Fix from $1,600 2017-02-13
Magelis Gtu Universal Panel Firmware HIGH 7.5
CVE-2016-8374

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all version…

Mitigation only
Fix from $1,950 2017-02-13
Knot Dns HIGH 8.6
CVE-2016-6171

Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for…

Fix: 2.3.0+
Fix from $1,950 2017-02-09
Debian Linux MEDIUM 5.5
CVE-2016-4570

The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption…

Fix: after 2.7
Fix from $1,600 2017-02-03
Debian Linux MEDIUM 5.5
CVE-2016-4571

The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consum…

Fix: after 2.7
Fix from $1,600 2017-02-03
Smartos MEDIUM 5.5
CVE-2016-9039

An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system…

No fix yet
Fix from $1,600 2017-01-31
Ntp HIGH 7.5
CVE-2015-7978EPSS 10%

NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via an ntpdc relist command, whi…

Fix: after 4.2.8
Fix from $1,950 2017-01-30
Moment MEDIUM 6.5
CVE-2016-4055EPSS 10%

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a lo…

Fix: 2.11.2+
Fix from $1,600 2017-01-23
Fengine S5800 Firmware MEDIUM 5.9
CVE-2017-5544EPSS 5%

An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password …

Mitigation only
Fix from $1,600 2017-01-23
Ubuntu Linux HIGH 7.5
CVE-2016-7426EPSS 12%

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote…

Fix: 4.2.8 / 4.3.94+
Fix from $1,950 2017-01-13
Ntp MEDIUM 6.5
CVE-2016-9310EPSS 11%

The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.

Fix: after 4.2.8
Fix from $1,600 2017-01-13
Samsung Mobile HIGH 7.5
CVE-2017-5351

Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of act…

Mitigation only
Fix from $1,950 2017-01-12
Chicken HIGH 7.5
CVE-2016-6831

The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This co…

Fix: after 4.11.0
Fix from $1,950 2017-01-10
Linux Kernel MEDIUM 5.5
CVE-2016-9685

Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memor…

Fix: after 4.5.0
Fix from $1,600 2016-12-28
Openssh HIGH 7.5
CVE-2016-8858EPSS 29%

The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) …

Patch available
Fix from $1,950 2016-12-09
Linux Kernel HIGH 7.5
CVE-2016-8666

The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspe…

Fix: 3.16.35 / 3.18.47+
Fix from $1,950 2016-10-16