Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Linux Kernel MEDIUM 5.5
CVE-2012-0879

The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to…

Fix: 2.6.33+
Fix from $1,600 2012-05-17
iOS HIGH 7.5
CVE-2012-0382

The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.…

Fix: 3.2.2sg / 3.4.1s+
Fix from $1,950 2012-03-29
Chrome MEDIUM 5.0
CVE-2011-3954

Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of …

Fix: 17.0.963.46+
Fix from $1,600 2012-02-09
Maradns HIGH 7.8
CVE-2012-0024

MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predict…

Fix: 1.3.07.12 / 1.4.08+
Fix from $1,950 2012-01-08
Jruby MEDIUM 5.0
CVE-2011-4838

JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent atta…

Fix: 1.6.5.1+
Fix from $1,600 2011-12-30
iOS HIGH 7.5
CVE-2011-1640

The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large number of LLDP Management Address (MA) TLVs, whic…

Fix: 12.2+
Fix from $1,950 2011-10-22
Linux Kernel HIGH 7.5
CVE-2011-2189EPSS 18%

net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, w…

Fix: after 2.6.32
Fix from $1,950 2011-10-10
HTTP Server HIGH 7.8
CVE-2011-3192EPSS 99%

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of ser…

Fix: 2.0.65 / 2.2.20+
Fix from $1,950 2011-08-29
Linux Kernel HIGH 7.5
CVE-2010-4251

The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows r…

Fix: 2.6.34+
Fix from $1,950 2011-05-26
Linux Kernel HIGH 7.5
CVE-2010-4805

The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows r…

Fix: 2.6.35+
Fix from $1,950 2011-05-26
Chrome HIGH 7.5
CVE-2011-0985

Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack …

Fix: 9.0.597.94+
Fix from $1,950 2011-02-10
iOS HIGH 7.8
CVE-2010-4686

CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" reques…

Fix: 15.0+
Fix from $1,950 2011-01-07
iOS HIGH 7.8
CVE-2010-4671

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of ser…

Fix: 15.0+
Fix from $1,950 2011-01-07
Linux Kernel HIGH 8.3
CVE-2010-3705

The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP pe…

Fix: 2.6.36+
Fix from $1,950 2010-11-26
Linux Kernel MEDIUM 5.5
CVE-2009-3621

net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-nam…

Fix: after 2.6.31.4
Fix from $1,600 2009-10-22
Internet Information Services MEDIUM 5.0
CVE-2009-2521EPSS 82%

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users…

Fix: after 7.0
Fix from $1,600 2009-09-04
Playstation 3 HIGH 7.5
CVE-2009-2541

The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a larg…

No fix yet
Fix from $1,950 2009-07-20
HTTP Server HIGH 7.1
CVE-2009-1891EPSS 17%

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is clo…

Fix: 2.0.64 / 2.2.12+
Fix from $1,950 2009-07-10
HTTP Server HIGH 7.1
CVE-2009-1890EPSS 16%

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured…

Fix: 2.2.12+
Fix from $1,950 2009-07-05
Ledgersmb HIGH 7.8
CVE-2008-4077

The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (reso…

Fix: 1.2.15+
Fix from $1,950 2008-09-15
Fortress Ssh MEDIUM 5.0
CVE-2008-0132EPSS 9%

Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the admini…

Fix: 5.0+
Fix from $1,600 2008-01-08
Linux Kernel HIGH 7.5
CVE-2006-7229

The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attackers to …

Mitigation only
Fix from $1,950 2007-11-15
7 Zip MEDIUM 6.8
CVE-2007-4725EPSS 6%

Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assis…

Fix: after 4.42
Fix from $1,600 2007-09-05
Firefox MEDIUM 5.0
CVE-2007-1377EPSS 17%

AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspec…

No fix yet
Fix from $1,600 2007-03-10
HTTP Server HIGH 7.8
CVE-2007-0086EPSS 10%

The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ…

Mitigation only
Fix from $1,950 2007-01-05
Ubuntu Linux MEDIUM 5.5
CVE-2006-5648

Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list a…

Patch available
Fix from $1,600 2006-12-14
Ubuntu Linux MEDIUM 5.5
CVE-2006-5649

Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to …

Patch available
Fix from $1,600 2006-12-14
WordPress MEDIUM 6.5
CVE-2006-6017

WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated…

Fix: after 2.0.5
Fix from $1,600 2006-11-21
Eudora Worldmail HIGH 7.5
CVE-2006-6025

QUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. NOTE: The…

No fix yet
Fix from $1,950 2006-11-21
Mdaemon HIGH 7.5
CVE-2006-5708

Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of servic…

Fix: after 9.50
Fix from $1,950 2006-11-04