Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Zxcvbn Ts HIGH 7.5
CVE-2023-34109

zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which …

Fix: 3.0.2+
Fix from $1,950 2023-06-07
Notation Go MEDIUM 5.7
CVE-2023-33957

notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of s…

Fix: 1.0.0+
Fix from $1,600 2023-06-06
Notation Go MEDIUM 6.5
CVE-2023-33958

notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of s…

Fix: 1.0.0+
Fix from $1,600 2023-06-06
Fast Xml Parser HIGH 7.5
CVE-2023-34104

fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sa…

Fix: 4.2.4+
Fix from $1,950 2023-06-06
Wcn685x 5 Firmware MEDIUM 5.5
CVE-2022-33303

Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queu…

Patch available
Fix from $1,600 2023-06-06
Firefox MEDIUM 6.5
CVE-2023-29544

If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentia…

Fix: 112.0+
Fix from $1,600 2023-06-02
Thunderbird MEDIUM 6.5
CVE-2023-0616

If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which cou…

Fix: 102.8+
Fix from $1,600 2023-06-02
Edjing Mix MEDIUM 5.5
CVE-2023-29735

An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.

No fix yet
Fix from $1,600 2023-05-30
Libreswan HIGH 7.5
CVE-2023-30570

pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode pack…

Fix: after 4.10
Fix from $1,950 2023-05-29
Curl MEDIUM 5.9
CVE-2023-28320

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at…

Fix: 8.1.0 / 11.7.9+
Fix from $1,600 2023-05-26
Fedora MEDIUM 5.5
CVE-2023-1981

A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.

No fix yet
Fix from $1,600 2023-05-26
Spring Boot HIGH 7.5
CVE-2023-20883

In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial…

Fix: 2.5.14+
Fix from $1,950 2023-05-26
Cf Deployment MEDIUM 5.9
CVE-2023-20882

In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applicat…

Fix: 0.266.0 / 29.0.0+
Fix from $1,600 2023-05-26
Mp4v2 MEDIUM 6.5
CVE-2023-33720

mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.

No fix yet
Fix from $1,600 2023-05-26
Synapse MEDIUM 6.5
CVE-2022-39374

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joine…

Fix: 1.68.0+
Fix from $1,600 2023-05-26
Fedora HIGH 7.5
CVE-2023-32067

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malf…

Fix: 1.19.1+
Fix from $1,950 2023-05-25
Htmlunit HIGH 7.5
CVE-2023-2798

Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web p…

Fix: 2.70.0+
Fix from $1,950 2023-05-25
Briar HIGH 7.5
CVE-2023-33980

Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a seri…

Fix: 1.4.22+
Fix from $1,950 2023-05-24
Garoon MEDIUM 6.5
CVE-2023-26595

Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service…

Fix: after 5.9.2
Fix from $1,600 2023-05-23
Bitcoin Core HIGH 7.5
CVE-2023-33297

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inv…

Fix: 24.1+
Fix from $1,950 2023-05-22
Enterprise Linux HIGH 7.5
CVE-2023-2295

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptabl…

Mitigation only
Fix from $1,950 2023-05-17
Http MEDIUM 5.3
CVE-2023-26044

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component c…

Fix: 1.9.0+
Fix from $1,600 2023-05-17
Android MEDIUM 5.5
CVE-2023-20930

In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lea…

Patch available
Fix from $1,600 2023-05-15
Android HIGH 7.8
CVE-2023-21110

In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local…

Patch available
Fix from $1,950 2023-05-15
Ua Java Legacy HIGH 7.5
CVE-2023-32787

The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that the…

Fix: 1.2.0 / 1.4.20+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-23447

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows …

Fix: 2.0+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-31409

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows …

Fix: 2.0+
Fix from $1,950 2023-05-15
Rocket.chat HIGH 7.5
CVE-2023-28356

A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot l…

Fix: 6.0.0+
Fix from $1,950 2023-05-11
My Cloud Home Firmware HIGH 7.5
CVE-2022-36329

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Dig…

Fix: 9.4.0-191+
Fix from $1,950 2023-05-10
Boxo HIGH 7.5
CVE-2023-25568

Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is a…

Patch available
Fix from $1,950 2023-05-10