Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Srelay HIGH 7.5
CVE-2024-25398

In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the servic…

No fix yet
Fix from $1,950 2024-02-27
Es5 Ext MEDIUM 5.5
CVE-2024-27088

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#…

Fix: 0.10.63+
Fix from $1,600 2024-02-26
Fedora HIGH 7.5
CVE-2024-23835

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excess…

Fix: 7.0.3+
Fix from $1,950 2024-02-26
Debian Linux HIGH 7.5
CVE-2024-22201

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.…

Fix: 9.4.54 / 10.0.20+
Fix from $1,950 2024-02-26
Active Iq Unified Manager HIGH 7.5
CVE-2024-1635

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user …

Mitigation only
Fix from $1,950 2024-02-19
Moodle HIGH 7.5
CVE-2024-25978

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

Fix: 4.1.9 / 4.2.6+
Fix from $1,950 2024-02-19
Mysql Server MEDIUM 6.5
CVE-2024-20962

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior …

Fix: after 8.2.0
Fix from $1,600 2024-02-17
Mysql Server MEDIUM 5.3
CVE-2024-20964

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.35…

Fix: after 8.2.0
Fix from $1,600 2024-02-17
Undici MEDIUM 6.5
CVE-2024-24750

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or co…

Fix: 6.6.1+
Fix from $1,600 2024-02-16
Squid HIGH 7.5
CVE-2024-25617EPSS 89%

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may b…

Fix: 6.5+
Fix from $1,950 2024-02-14
Enterprise Linux HIGH 7.5
CVE-2023-50868EPSS 82%

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of se…

Fix: 4.8.5 / 4.9.3+
Fix from $1,950 2024-02-14
Thunderbolt Dch Driver MEDIUM 5.5
CVE-2023-25769

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to poten…

Fix: 88+
Fix from $1,600 2024-02-14
Superset MEDIUM 6.5
CVE-2024-23952

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be trig…

Fix: 2.1.3 / 3.0.2+
Fix from $1,600 2024-02-14
Debian Linux HIGH 7.5
CVE-2024-24814

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Re…

Fix: after 2.4.15.1
Fix from $1,950 2024-02-13
Asp.net Core HIGH 7.5
CVE-2024-21386

.NET Denial of Service Vulnerability

Fix: 6.0.27 / 7.0.16+
Fix from $1,950 2024-02-13
Windows 11 22h2 HIGH 7.5
CVE-2024-21342

Windows DNS Client Denial of Service Vulnerability

Fix: 10.0.22621.3155 / 10.0.25398.709+
Fix from $1,950 2024-02-13
Niagara Framework HIGH 7.5
CVE-2024-1309

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niag…

Fix: 3.8.1+
Fix from $1,950 2024-02-13
F30 03x Yy \(com\) Firmware HIGH 7.5
CVE-2024-24781

An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic o…

Fix: after 24.14
Fix from $1,950 2024-02-13
Exiv2 MEDIUM 5.0
CVE-2024-25112

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was fo…

Patch available
Fix from $1,600 2024-02-12
Fedora MEDIUM 5.3
CVE-2023-6681

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and d…

Fix: 1.5.1+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 6.5
CVE-2023-41706

Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availabilit…

Fix: 7.6.3 / 7.10.6+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 6.5
CVE-2023-41707

Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please …

Fix: 7.6.3 / 7.10.6+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 6.5
CVE-2023-41705

Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please d…

Fix: 7.6.3 / 7.10.6+
Fix from $1,600 2024-02-12
Samly CRITICAL 9.8
CVE-2024-25718

In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control b…

Fix: 1.4.0+
Fix from $2,300 2024-02-11
Envoy MEDIUM 5.3
CVE-2024-23323

Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increa…

Fix: 1.26.7 / 1.27.3+
Fix from $1,600 2024-02-09
Bento4 MEDIUM 6.5
CVE-2024-25451

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

No fix yet
Fix from $1,600 2024-02-09
Bento4 MEDIUM 5.5
CVE-2024-25452

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

No fix yet
Fix from $1,600 2024-02-09
Backuply HIGH 7.5
CVE-2024-0842

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6…

Fix: 1.2.6+
Fix from $1,950 2024-02-09
Integration Bus MEDIUM 6.5
CVE-2024-22332

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: …

Fix: after 10.1.0.2
Fix from $1,600 2024-02-09
Sterling B2b Integrator MEDIUM 6.5
CVE-2023-32341

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to…

Fix: after 6.1.2.3
Fix from $1,600 2024-02-09