Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified MEDIUM 5.3
CVE-2023-50966

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2…

Mitigation only
Fix from $1,600 2024-03-19
Unclassified HIGH 7.5
CVE-2024-26369

An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWrit…

Patch available
Fix from $1,950 2024-03-19
Discourse MEDIUM 6.5
CVE-2024-27085

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily la…

Fix: 3.2.0 / 3.3.0+
Fix from $1,600 2024-03-15
Discourse MEDIUM 6.5
CVE-2024-27100

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting…

Fix: 3.2.1 / 3.3.0+
Fix from $1,600 2024-03-15
Discourse HIGH 7.5
CVE-2024-24827

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker…

Fix: 3.2.0 / 3.3.0+
Fix from $1,950 2024-03-15
Tls Listener HIGH 7.5
CVE-2024-28854

tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-listener, a malicious user can…

Fix: 0.10.0+
Fix from $1,950 2024-03-15
Mattermost Server MEDIUM 6.5
CVE-2024-28053

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an …

Fix: 8.1.10+
Fix from $1,600 2024-03-15
Mattermost Mobile MEDIUM 6.5
CVE-2024-24975

Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the…

Fix: 2.13.0+
Fix from $1,600 2024-03-15
Unclassified MEDIUM 6.8
CVE-2023-35191

Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of service via net…

Mitigation only
Fix from $1,600 2024-03-14
Quiche MEDIUM 5.3
CVE-2024-1410

Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excess…

Fix: 0.19.2+
Fix from $1,600 2024-03-12
Quiche HIGH 7.5
CVE-2024-1765

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usa…

Fix: 0.19.2+
Fix from $1,950 2024-03-12
.net HIGH 7.5
CVE-2024-26190

Microsoft QUIC Denial of Service Vulnerability

Fix: 7.0.17 / 7.3.12+
Fix from $1,950 2024-03-12
.net HIGH 7.5
CVE-2024-21392

.NET and Visual Studio Denial of Service Vulnerability

Fix: 7.0.17 / 7.3.12+
Fix from $1,950 2024-03-12
Fedora MEDIUM 5.9
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Enc…

Fix: 2.0.7 / 4.15.5+
Fix from $1,600 2024-03-09
Jwx MEDIUM 6.8
CVE-2024-28122

JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a t…

Fix: 1.2.29 / 2.0.21+
Fix from $1,600 2024-03-09
Ipados HIGH 7.8
CVE-2024-23265

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4,…

Fix: 1.1 / 10.4+
Fix from $1,950 2024-03-08
Ipados MEDIUM 6.5
CVE-2024-23259

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Proce…

Fix: 14.4 / 16.7.6+
Fix from $1,600 2024-03-08
Linux Kernel HIGH 7.8
CVE-2023-52602

In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds Read in dtSearch Currently while searching for curr…

Fix: 4.19.307 / 5.4.269+
Fix from $1,950 2024-03-06
Arubaos MEDIUM 5.3
CVE-2024-25615

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exp…

Fix: 8.10.0.10 / 8.11.2.1+
Fix from $1,600 2024-03-05
Libheif HIGH 7.5
CVE-2024-25269

libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.

Fix: after 1.17.6
Fix from $1,950 2024-03-05
Debian Linux HIGH 7.5
CVE-2024-27354

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate c…

Fix: 1.0.23 / 2.0.47+
Fix from $1,950 2024-03-01
Debian Linux HIGH 7.5
CVE-2024-27355

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a ce…

Fix: 1.0.23 / 2.0.47+
Fix from $1,950 2024-03-01
Mattermost Server MEDIUM 6.5
CVE-2024-24988

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very lon…

Fix: 8.1.8 / 9.1.5+
Fix from $1,600 2024-02-29
Nx Os HIGH 8.6
CVE-2024-20321

A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,950 2024-02-29
Imm Management Package MEDIUM 5.3
CVE-2024-20344

A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could …

Fix: 1.0.11-1582+
Fix from $1,600 2024-02-29
Jose4j MEDIUM 6.5
CVE-2023-51775

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Fix: 0.9.4+
Fix from $1,600 2024-02-29
Rack HIGH 7.5
CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Respo…

Fix: 2.2.8.1 / 3.0.9.1+
Fix from $1,950 2024-02-29
Linux Kernel HIGH 8.2
CVE-2021-47023

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix port event handling on init For some reason there m…

Fix: 5.10.37 / 5.11.21+
Fix from $1,950 2024-02-28
Linux Kernel HIGH 7.8
CVE-2021-47010

In the Linux kernel, the following vulnerability has been resolved: net: Only allow init netns to set default tcp cong to a restricted algo tcp_set…

Fix: 4.19.191 / 5.4.119+
Fix from $1,950 2024-02-28
Linux Kernel MEDIUM 5.5
CVE-2021-46939

In the Linux kernel, the following vulnerability has been resolved: tracing: Restructure trace_clock_global() to never block It was reported that a…

Fix: 4.4.269 / 4.9.269+
Fix from $1,600 2024-02-27