Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Leap MEDIUM 6.8
CVE-2016-6172

PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary…

Fix: after 4.0.0
Fix from $1,600 2016-09-26
Ubuntu Linux MEDIUM 5.5
CVE-2016-5403

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QE…

Patch available
Fix from $1,600 2016-08-02
Webkit MEDIUM 6.5
CVE-2016-4592

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to cause a denial of service (memory consumption…

Fix: 2.10.5+
Fix from $1,600 2016-07-22
Libvirt MEDIUM 6.5
CVE-2014-3672

The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing t…

Fix: after 1.2.21
Fix from $1,600 2016-05-25
Fedora MEDIUM 6.0
CVE-2016-4037

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU…

Fix: after 2.5.1
Fix from $1,600 2016-05-23
Safari MEDIUM 6.5
CVE-2016-1784

The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of ser…

Fix: 9.1 / 9.2+
Fix from $1,600 2016-03-24
Nginx MEDIUM 5.3
CVE-2016-0747EPSS 8%

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial …

Fix: 1.8.1 / 1.9.10+
Fix from $1,600 2016-02-15
Ubuntu Linux HIGH 8.6
CVE-2015-1779EPSS 7%

The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket p…

Patch available
Fix from $1,950 2016-01-12
Openssh HIGH 8.1
CVE-2015-5600EPSS 9%

The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive dev…

Fix: after 6.9
Fix from $1,950 2015-08-03
Java HIGH 7.5
CVE-2015-1916

Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and th…

No fix yet
Fix from $1,950 2015-07-02
Multilink Ml810 Firmware HIGH 7.8
CVE-2014-5418

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmwar…

Fix: after 5.2.0
Fix from $1,950 2015-01-17
Fedora MEDIUM 5.0
CVE-2014-8124

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached sess…

Fix: 2014.1.3 / 2014.2.1+
Fix from $1,600 2014-12-12
Seil B1 Firmware HIGH 7.5
CVE-2014-7255

Internet Initiative Japan Inc. SEIL Series routers SEIL/X1 2.50 through 4.62, SEIL/X2 2.50 through 4.62, SEIL/B1 2.50 through 4.62, and SEIL/x86 Fuji…

Fix: after 4.62
Fix from $1,950 2014-12-05
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-3407

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HT…

Fix: after 9.3
Fix from $1,600 2014-11-28
Linux Kernel MEDIUM 5.5
CVE-2014-8559

The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local use…

Fix: after 3.17.2
Fix from $1,600 2014-11-10
Linux Kernel MEDIUM 5.5
CVE-2014-3690

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control regis…

Fix: 3.17.2+
Fix from $1,600 2014-11-10
Linux Kernel HIGH 7.5
CVE-2014-3687EPSS 9%

The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attacke…

Fix: 3.2.64 / 3.4.107+
Fix from $1,950 2014-11-10
Linux Kernel MEDIUM 5.5
CVE-2014-7970

The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot direct…

Fix: after 3.17
Fix from $1,600 2014-10-13
Unified Presence Server MEDIUM 5.0
CVE-2014-3328

The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of service via a TCP SYN flood, aka Bu…

Mitigation only
Fix from $1,600 2014-07-26
Adaptive Security Appliance Software MEDIUM 5.4
CVE-2013-5567

Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering…

Fix: after 8.4
Fix from $1,600 2014-07-14
Scada Data Gateway MEDIUM 5.0
CVE-2014-2342

Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafte…

Fix: after 3.00.0633
Fix from $1,600 2014-05-30
Firefox MEDIUM 5.0
CVE-2014-1500

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang)…

Fix: 2.25 / 28.0+
Fix from $1,600 2014-03-19
Linux Kernel HIGH 7.8
CVE-2012-6638

The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (ke…

Fix: 3.0.38 / 3.2.24+
Fix from $1,950 2014-02-15
Linux Kernel MEDIUM 5.5
CVE-2013-2128

The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to …

Fix: 2.6.34+
Fix from $1,600 2013-06-07
Modicon M340 Bmx Noc 0401 Firmware MEDIUM 5.0
CVE-2013-2763

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: th…

Mitigation only
Fix from $1,600 2013-04-04
Openssh HIGH 7.5
CVE-2010-5107EPSS 17%

The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which make…

Fix: after 6.1
Fix from $1,950 2013-03-07
Ubuntu Linux MEDIUM 6.5
CVE-2012-0260

The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumpti…

Patch available
Fix from $1,600 2012-06-05
Linux Kernel MEDIUM 5.5
CVE-2011-2906

Integer signedness error in the pmcraid_ioctl_passthrough function in drivers/scsi/pmcraid.c in the Linux kernel before 3.1 might allow local users t…

Fix: 3.1+
Fix from $1,600 2012-05-24
Linux Kernel MEDIUM 5.5
CVE-2011-2918

The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK even…

Fix: 3.1+
Fix from $1,600 2012-05-24
Linux Kernel MEDIUM 5.5
CVE-2012-0058

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that tr…

Fix: 3.2.2+
Fix from $1,600 2012-05-17