Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
GitLab HIGH 7.5
CVE-2022-3759

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 before 15.7.6, …

Fix: 15.6.7 / 15.7.6+
Fix from $1,950 2023-02-13
GitLab HIGH 7.5
CVE-2023-0518

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, …

Fix: 15.6.7 / 15.7.6+
Fix from $1,950 2023-02-13
GitLab MEDIUM 6.5
CVE-2022-3411

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an auth…

Fix: 15.6.7 / 15.7.6+
Fix from $1,600 2023-02-13
Android MEDIUM 5.5
CVE-2022-47354

In log service, there is a missing permission check. This could lead to local denial of service in log service.

Mitigation only
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47355

In log service, there is a missing permission check. This could lead to local denial of service in log service.

No fix yet
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47356

In log service, there is a missing permission check. This could lead to local denial of service in log service.

No fix yet
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47370

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

No fix yet
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-38674

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

No fix yet
Fix from $1,600 2023-02-12
Csr8811 Firmware HIGH 7.5
CVE-2022-40513

Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.

Mitigation only
Fix from $1,950 2023-02-12
Go Unixfs HIGH 7.5
CVE-2023-23625

go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause pan…

Fix: 0.4.3+
Fix from $1,950 2023-02-09
Go Unixfsnode HIGH 7.5
CVE-2023-23631

github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot t…

Fix: 1.5.2+
Fix from $1,950 2023-02-09
Activerecord HIGH 7.5
CVE-2022-44566

A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit sign…

Fix: 6.1.7.1 / 7.0.4.1+
Fix from $1,950 2023-02-09
Rack HIGH 7.5
CVE-2022-44570

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsin…

Fix: 2.0.9.2 / 2.1.4.2+
Fix from $1,950 2023-02-09
Rack HIGH 7.5
CVE-2022-44571

There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This coul…

Fix: 2.0.9.2 / 2.1.4.2+
Fix from $1,950 2023-02-09
Rack HIGH 7.5
CVE-2022-44572

A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker t…

Fix: 2.0.9.2 / 2.1.4.2+
Fix from $1,950 2023-02-09
Rails HIGH 7.5
CVE-2023-22792

A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a sp…

Fix: 6.0.6.1 / 6.1.7.1+
Fix from $1,950 2023-02-09
Rails HIGH 7.5
CVE-2023-22795

A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP I…

Fix: 6.1.7.1 / 7.0.4.1+
Fix from $1,950 2023-02-09
Activesupport HIGH 7.5
CVE-2023-22796

A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can …

Fix: 6.1.7.1 / 7.0.4.1+
Fix from $1,950 2023-02-09
Globalid HIGH 7.5
CVE-2023-22799

A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expres…

Fix: 1.0.1+
Fix from $1,950 2023-02-09
Opentelemetry Go Contrib HIGH 7.5
CVE-2023-25151

opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/…

No fix yet
Fix from $1,950 2023-02-08
Dt100112 Firmware MEDIUM 6.5
CVE-2022-40480

Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service…

Mitigation only
Fix from $1,600 2023-02-08
Switcher Client HIGH 7.5
CVE-2023-23925

Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy match operatio…

Fix: 3.1.4+
Fix from $1,950 2023-02-03
Enterprise Sonic Distribution HIGH 7.5
CVE-2023-24574

Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication component. An u…

Fix: 4.0.3+
Fix from $1,950 2023-02-02
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22664

On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and…

Fix: 16.1.3.3 / 17.0.0.2+
Fix from $1,950 2023-02-01
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2023-23552

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP A…

Fix: 14.1.5.3 / 15.1.8+
Fix from $1,950 2023-02-01
Cmark Gfm HIGH 7.5
CVE-2023-22486

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomia…

Fix: 0.29.0.gfm.7+
Fix from $1,950 2023-01-26
Android MEDIUM 5.5
CVE-2023-20908

In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of serv…

Mitigation only
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2023-20922

In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service …

Mitigation only
Fix from $1,600 2023-01-26
Bind HIGH 7.5
CVE-2022-3094EPSS 13%

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack …

Fix: 9.16.37 / 9.18.11+
Fix from $1,950 2023-01-26
Gateway MEDIUM 6.5
CVE-2022-27507

Authenticated denial of service

Fix: 12.1-55.278 / 12.1-64.17+
Fix from $1,600 2023-01-26