Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Synapse MEDIUM 5.3
CVE-2022-41952

Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting co…

Fix: 1.53.0+
Fix from $1,600 2022-11-22
Free5gc HIGH 7.5
CVE-2022-38871

In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.

No fix yet
Fix from $1,950 2022-11-18
Wbce Cms HIGH 7.5
CVE-2022-4006

A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the fil…

Patch available
Fix from $1,950 2022-11-15
Secure Firewall Management Center HIGH 7.5
CVE-2022-20854

A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software cou…

Fix: after 6.7.0.3
Fix from $1,950 2022-11-15
Diffie Hellman Key Exchange HIGH 7.5
CVE-2022-40735

The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 1…

Mitigation only
Fix from $1,950 2022-11-14
Pillow HIGH 7.5
CVE-2022-45199

Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.

Fix: 9.3.0+
Fix from $1,950 2022-11-14
Support MEDIUM 5.5
CVE-2022-30691

Uncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potentially …

Fix: 22.02.28+
Fix from $1,600 2022-11-11
GitLab MEDIUM 5.3
CVE-2022-3818

An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 p…

Fix: 15.3.5 / 15.4.4+
Fix from $1,600 2022-11-10
Splunk MEDIUM 6.5
CVE-2022-43572

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HE…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk MEDIUM 6.5
CVE-2022-43564

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a deni…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Identity Services Engine MEDIUM 5.3
CVE-2022-20937

A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote at…

Fix: 2.7.0+
Fix from $1,600 2022-11-04
Email Security Appliance HIGH 7.5
CVE-2022-20960

A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial o…

Fix: 14.2.1-015 / 14.3.0-020+
Fix from $1,950 2022-11-04
Debian Linux MEDIUM 6.5
CVE-2022-43238

Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attacker…

No fix yet
Fix from $1,600 2022-11-02
Ipados HIGH 7.5
CVE-2022-32927

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining a malicio…

Fix: 15.7.1+
Fix from $1,950 2022-11-01
Conduit Hyper HIGH 7.5
CVE-2022-39294

conduit-hyper integrates a conduit application with the hyper server. Prior to version 0.4.2, `conduit-hyper` did not check any limit on a request's …

Fix: 0.4.2+
Fix from $1,950 2022-10-31
Zephyr HIGH 7.5
CVE-2022-2741

The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vulnerable node. The frame must h…

Fix: after 3.1.0
Fix from $1,950 2022-10-31
Ubuntu Linux HIGH 7.5
CVE-2022-40617

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermedia…

Fix: 3.11.20 / 4.3.15+
Fix from $1,950 2022-10-31
Iotdb HIGH 7.5
CVE-2022-43766

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP que…

Fix: after 0.13.2
Fix from $1,950 2022-10-26
GitLab HIGH 7.5
CVE-2022-3639

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 1…

Fix: 15.1.6 / 15.2.4+
Fix from $1,950 2022-10-21
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2022-41806

In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with IPv6/IPv4 translation rules is…

Fix: 15.1.5.1 / 16.1.3.2+
Fix from $1,950 2022-10-19
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-41833

In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause T…

Fix: after 13.1.5
Fix from $1,950 2022-10-19
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-41770

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-…

Fix: 14.1.5.1 / 15.1.7+
Fix from $1,600 2022-10-19
Supybot Fedora MEDIUM 5.3
CVE-2020-15853

supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a while to run, and zodbot stops re…

Mitigation only
Fix from $1,600 2022-10-18
Debian Linux HIGH 7.5
CVE-2022-3517

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand func…

Fix: 3.0.5+
Fix from $1,950 2022-10-17
GitLab HIGH 7.5
CVE-2022-3283

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3…

Fix: 15.2.5 / 15.3.4+
Fix from $1,950 2022-10-17
GitLab MEDIUM 6.5
CVE-2022-2455

A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2…

Fix: 15.1.6 / 15.2.4+
Fix from $1,600 2022-10-17
GitLab HIGH 7.5
CVE-2022-2931

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all…

Fix: 15.1.6 / 15.2.4+
Fix from $1,950 2022-10-17
Android MEDIUM 5.5
CVE-2022-39128

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39123

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39124

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-10-14