Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Android MEDIUM 5.5
CVE-2022-39125

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

No fix yet
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39126

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-39127

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38679

In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privi…

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38687

In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional executi…

No fix yet
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38677

In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privile…

No fix yet
Fix from $1,600 2022-10-14
Istio HIGH 7.5
CVE-2022-39278

Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions …

Fix: 1.13.9 / 1.14.5+
Fix from $1,950 2022-10-13
Debian Linux HIGH 7.5
CVE-2022-41404

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via …

Fix: 0.5.4+
Fix from $1,950 2022-10-11
Android MEDIUM 5.5
CVE-2022-20425

In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to…

Patch available
Fix from $1,600 2022-10-11
Traefik HIGH 7.5
CVE-2022-39271

Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerabi…

Fix: 2.8.8+
Fix from $1,950 2022-10-11
Nucleus Net HIGH 7.5
CVE-2022-38371

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BAC…

Fix: after 2.3
Fix from $1,950 2022-10-11
Dependency Parser HIGH 7.5
CVE-2022-39280

dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expressi…

Fix: 0.5.1+
Fix from $1,950 2022-10-06
Goflow HIGH 7.5
CVE-2022-2529

sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packe…

Fix: 3.4.4+
Fix from $1,950 2022-09-30
Rtl8195am Firmware HIGH 7.5
CVE-2022-34326

In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer tas…

Fix: 2022-06-20+
Fix from $1,950 2022-09-27
Fedora HIGH 7.5
CVE-2022-3204

A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegatio…

Fix: after 1.16.2
Fix from $1,950 2022-09-26
Ipados HIGH 7.5
CVE-2022-32790

This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Bi…

Fix: 8.6 / 10.15.7+
Fix from $1,950 2022-09-23
Mattermost Server MEDIUM 6.5
CVE-2022-3257

Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which a…

Fix: 7.2.0+
Fix from $1,600 2022-09-23
Keylime MEDIUM 5.5
CVE-2022-23951

In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.

Fix: 6.3.0+
Fix from $1,600 2022-09-21
Integrated Lights Out 5 Firmware HIGH 8.8
CVE-2022-28639

A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a lo…

Fix: 2.72+
Fix from $1,950 2022-09-20
Clearpass Policy Manager HIGH 7.5
CVE-2022-37884

A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operations wh…

Fix: 6.9.12 / 6.10.7+
Fix from $1,950 2022-09-20
Mediawiki HIGH 7.5
CVE-2022-28204

A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3A…

Fix: 1.37.2+
Fix from $1,950 2022-09-19
Debian Linux HIGH 7.5
CVE-2022-40150

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl…

Fix: after 1.4.0
Fix from $1,950 2022-09-16
Cmark Gfm MEDIUM 6.5
CVE-2022-39209

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time…

Fix: 0.29.0.gfm.6+
Fix from $1,600 2022-09-15
Cargo MEDIUM 6.5
CVE-2022-36114

Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed…

Fix: 0.65.0+
Fix from $1,600 2022-09-14
Qemu HIGH 7.8
CVE-2022-2962

A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame,…

Fix: after 7.1.0
Fix from $1,950 2022-09-13
Fedora HIGH 7.5
CVE-2022-38013

.NET Core and Visual Studio Denial of Service Vulnerability

Patch available
Fix from $1,950 2022-09-13
Cms8000 Firmware HIGH 7.5
CVE-2022-38100

The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issu…

Mitigation only
Fix from $1,950 2022-09-13
Ruggedcom Ros MEDIUM 5.3
CVE-2022-39158

A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCO…

Fix: 5.6.0+
Fix from $1,600 2022-09-13
Indy Node HIGH 7.5
CVE-2022-31006

indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-no…

Fix: after 1.12.6
Fix from $1,950 2022-09-09
Mattermost Server MEDIUM 6.5
CVE-2022-3147

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated…

Fix: 7.1.0+
Fix from $1,600 2022-09-09