Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Netweaver Application Server Java HIGH 7.5
CVE-2024-34688

Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, whic…

Patch available
Fix from $1,950 2024-06-11
Netweaver Application Server Abap MEDIUM 6.5
CVE-2024-33001

SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of th…

Patch available
Fix from $1,600 2024-06-11
Visionos MEDIUM 6.5
CVE-2024-27812

A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service.

Fix: 1.2+
Fix from $1,600 2024-06-10
Ipados MEDIUM 6.5
CVE-2024-27800

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monter…

Fix: 1.2 / 10.5+
Fix from $1,600 2024-06-10
Unclassified HIGH 7.5
CVE-2023-51847

An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsaf…

Mitigation only
Fix from $1,950 2024-06-06
Anythingllm MEDIUM 6.5
CVE-2024-3153

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of serv…

Fix: 1.0.0+
Fix from $1,600 2024-06-06
Oneflow HIGH 7.5
CVE-2024-36743

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.

Mitigation only
Fix from $1,950 2024-06-06
Unclassified HIGH 7.5
CVE-2024-33655

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to …

Patch available
Fix from $1,950 2024-06-06
Ubuntu Linux HIGH 7.8
CVE-2022-28657

Apport does not disable python crash handler before entering chroot

Fix: 2.21.0+
Fix from $1,950 2024-06-04
Envoy MEDIUM 6.5
CVE-2024-34364

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP c…

Fix: 1.27.6 / 1.28.4+
Fix from $1,600 2024-06-04
Unclassified HIGH 7.1
CVE-2024-5422

An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertech…

Mitigation only
Fix from $1,950 2024-06-04
Unclassified HIGH 7.5
CVE-2023-30311

An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

Mitigation only
Fix from $1,950 2024-05-28
Unclassified MEDIUM 6.5
CVE-2024-22588

Kwik commit 745fd4e2 does not discard unused encryption keys.

No fix yet
Fix from $1,600 2024-05-24
Linux Kernel HIGH 7.1
CVE-2021-47371

In the Linux kernel, the following vulnerability has been resolved: nexthop: Fix memory leaks in nexthop notification chain listeners syzkaller dis…

Fix: 5.14.9+
Fix from $1,950 2024-05-21
Linux Kernel HIGH 7.1
CVE-2021-47368

In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() sto…

Fix: 5.4.150 / 5.10.70+
Fix from $1,950 2024-05-21
Linux Kernel MEDIUM 6.2
CVE-2021-47329

In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix resource leak in case of probe failure The driver doesn…

Fix: 5.4.134 / 5.10.52+
Fix from $1,600 2024-05-21
Linux Kernel HIGH 8.4
CVE-2021-47313

In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init It's a classic ex…

Fix: 5.12.19 / 5.13.4+
Fix from $1,950 2024-05-21
Linux Kernel HIGH 7.5
CVE-2021-47295

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix memory leak in tcindex_partial_destroy_work Syzbot reported mem…

Fix: 5.4.136 / 5.10.54+
Fix from $1,950 2024-05-21
Linux Kernel MEDIUM 5.5
CVE-2021-47238

In the Linux kernel, the following vulnerability has been resolved: net: ipv4: fix memory leak in ip_mc_add1_src BUG: memory leak unreferenced obje…

Fix: 3.3 / 3.17+
Fix from $1,600 2024-05-21
Unclassified MEDIUM 5.3
CVE-2024-35194

Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaust…

Patch available
Fix from $1,600 2024-05-20
Unclassified HIGH 7.5
CVE-2024-34953

An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm file

No fix yet
Fix from $1,950 2024-05-20
Linux Kernel HIGH 7.8
CVE-2024-35948

In the Linux kernel, the following vulnerability has been resolved: bcachefs: Check for journal entries overruning end of sb clean section Fix a mi…

Fix: 6.9+
Fix from $1,950 2024-05-20
Linux Kernel MEDIUM 5.5
CVE-2024-35799

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent crash when disable stream [Why] Disabling stream encod…

Fix: 6.6.26 / 6.7.12+
Fix from $1,600 2024-05-17
Linux Kernel MEDIUM 5.5
CVE-2023-52672

In the Linux kernel, the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commit c73be61cede5 ("pipe: Add ge…

Fix: 5.10.210 / 5.15.149+
Fix from $1,600 2024-05-17
Unclassified HIGH 7.5
CVE-2024-5055

Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to proces…

Mitigation only
Fix from $1,950 2024-05-17
Unclassified HIGH 7.5
CVE-2024-5052

Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port…

Mitigation only
Fix from $1,950 2024-05-17
Unclassified HIGH 7.5
CVE-2024-21823

Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow…

Mitigation only
Fix from $1,950 2024-05-16
Rexml MEDIUM 5.3
CVE-2024-35176

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an att…

Fix: 3.2.7+
Fix from $1,600 2024-05-16
Unclassified MEDIUM 5.3
CVE-2024-35185

Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack vi…

Patch available
Fix from $1,600 2024-05-16
Gvisor MEDIUM 6.5
CVE-2023-7258

A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible…

Fix: 20231204.0+
Fix from $1,600 2024-05-15