Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Openvpn HIGH 7.5
CVE-2020-20813

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

Fix: after 2.4.7
Fix from $1,950 2023-08-22
Binutils HIGH 8.8
CVE-2020-19726

An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a…

No fix yet
Fix from $1,950 2023-08-22
Zziplib MEDIUM 5.5
CVE-2020-18770

An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.

No fix yet
Fix from $1,600 2023-08-22
Tl Wr1041n V2 Firmware HIGH 7.5
CVE-2023-39748

An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET reque…

No fix yet
Fix from $1,950 2023-08-21
Linux Kernel MEDIUM 6.0
CVE-2023-4394

A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux Kernel. This flaw allows a lo…

Fix: 6.0+
Fix from $1,600 2023-08-17
Websphere Application Server HIGH 7.5
CVE-2023-38737

IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted reque…

Fix: after 23.0.0.7
Fix from $1,950 2023-08-16
Android MEDIUM 5.5
CVE-2023-21280

In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local…

Patch available
Fix from $1,600 2023-08-14
Txseries For Multiplatform HIGH 7.5
CVE-2023-38741

IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual r…

Mitigation only
Fix from $1,950 2023-08-14
Node Worker Threads Pool MEDIUM 6.5
CVE-2021-29057

An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.

No fix yet
Fix from $1,600 2023-08-11
Xmp Toolkit Software Development Kit MEDIUM 5.5
CVE-2023-38210

Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated attacker could leverage this …

Fix: after 2022.06
Fix from $1,600 2023-08-10
Fedora HIGH 7.5
CVE-2023-38180 KEVEPSS 14%

.NET and Visual Studio Denial of Service Vulnerability

Fix: 2.1.40 / 6.0.21+
Fix from $1,950 2023-08-08
.net HIGH 7.5
CVE-2023-38178

.NET Core and Visual Studio Denial of Service Vulnerability

Fix: 17.2.18 / 17.4.10+
Fix from $1,950 2023-08-08
Go MEDIUM 5.3
CVE-2023-29409

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of R…

Fix: 1.19.12 / 1.20.7+
Fix from $1,600 2023-08-02
Kepserverex HIGH 7.5
CVE-2023-3825

PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource cons…

Fix: after 6.14.263
Fix from $1,950 2023-07-31
Poppler MEDIUM 5.5
CVE-2023-34872

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file…

Fix: 23.06.0+
Fix from $1,600 2023-07-31
Discourse MEDIUM 6.5
CVE-2023-38498

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passe…

Fix: 3.0.6+
Fix from $1,600 2023-07-28
Openstack Platform MEDIUM 6.5
CVE-2023-3637

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security gr…

Mitigation only
Fix from $1,600 2023-07-25
Enterprise Linux HIGH 7.5
CVE-2023-38200

A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections…

Patch available
Fix from $1,950 2023-07-24
Okhttp Brotli MEDIUM 5.9
CVE-2023-3782

DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotl…

No fix yet
Fix from $1,600 2023-07-19
Chakracore MEDIUM 5.5
CVE-2023-37140

ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount().

No fix yet
Fix from $1,600 2023-07-18
Chakracore MEDIUM 5.5
CVE-2023-37141

ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray().

No fix yet
Fix from $1,600 2023-07-18
Chakracore MEDIUM 5.5
CVE-2023-37142

ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().

No fix yet
Fix from $1,600 2023-07-18
Chakracore MEDIUM 5.5
CVE-2023-37143

ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp().

Patch available
Fix from $1,600 2023-07-18
Goproxy HIGH 7.5
CVE-2023-37788

goproxy v1.1 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors.

No fix yet
Fix from $1,950 2023-07-18
Kinetix 5700 Firmware HIGH 7.5
CVE-2023-2263

The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  The new ENIP connections cannot be established if im…

Mitigation only
Fix from $1,950 2023-07-18
Ngiflib MEDIUM 6.5
CVE-2022-30858

An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0

No fix yet
Fix from $1,600 2023-07-17
Avro HIGH 7.5
CVE-2023-37475

Hamba avro is a go lang encoder/decoder implementation of the avro codec specification. In affected versions a well-crafted string passed to avro's `…

Fix: 2.13.0+
Fix from $1,950 2023-07-17
Mattermost Server MEDIUM 6.5
CVE-2023-3593

Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.

Fix: 7.8.7 / 7.9.5+
Fix from $1,600 2023-07-17
C\# Language Server Protocol HIGH 7.5
CVE-2022-4952

A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects th…

Fix: 0.19.7+
Fix from $1,950 2023-07-17
Discourse HIGH 7.5
CVE-2023-36818

Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of serv…

Patch available
Fix from $1,950 2023-07-14