Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Connect Secure HIGH 7.5
CVE-2021-22965

A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed r…

Fix: 9.1+
Fix from $1,950 2021-11-19
Distribution Of Openvino Toolkit MEDIUM 5.5
CVE-2021-33073

Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to pote…

Fix: 2021.4+
Fix from $1,600 2021-11-17
Hardware Accelerated Execution Manager HIGH 8.4
CVE-2021-0180

Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privileg…

Fix: 7.6.6+
Fix from $1,950 2021-11-17
Hardware Accelerated Execution Manager MEDIUM 6.2
CVE-2021-0182

Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable informat…

Fix: 7.6.6+
Fix from $1,600 2021-11-17
Debian Linux MEDIUM 6.5
CVE-2021-41229

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will …

No fix yet
Fix from $1,600 2021-11-12
Debian Linux MEDIUM 6.5
CVE-2021-3912

OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat…

Fix: 1.3.0+
Fix from $1,600 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3908

OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3909

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Big Ip Access Policy Manager HIGH 7.5
CVE-2002-20001EPSS 23%

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys,…

Fix: 16.1.4 / 17.1.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-43173

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feedin…

Fix: 0.10.2+
Fix from $1,950 2021-11-09
Fortiweb HIGH 7.5
CVE-2021-36187

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial o…

Fix: after 6.3.15
Fix from $1,950 2021-11-02
Image Processing MEDIUM 5.5
CVE-2020-21573

An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.

Mitigation only
Fix from $1,600 2021-11-02
Fortiportal MEDIUM 6.5
CVE-2021-32595

Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to…

Fix: 5.3.7 / 6.0.6+
Fix from $1,600 2021-11-02
Fluentd HIGH 7.5
CVE-2021-41186

Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd…

Fix: after 1.14.1
Fix from $1,950 2021-10-29
macOS MEDIUM 6.5
CVE-2020-10005

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. An attacker in a privileged ne…

Fix: 11.0.1+
Fix from $1,600 2021-10-28
Secure Firewall Threat Defense HIGH 7.5
CVE-2021-34792

A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow …

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,950 2021-10-27
Adaptive Security Appliance HIGH 7.5
CVE-2021-40117

A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software cou…

Fix: 6.2.3.17 / 6.4.0.13+
Fix from $1,950 2021-10-27
Secure Firewall Threat Defense MEDIUM 6.5
CVE-2021-40125

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower…

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,600 2021-10-27
Capi Release HIGH 7.5
CVE-2021-22101

Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers …

Fix: 1.118.0 / 16.24.0+
Fix from $1,950 2021-10-27
Freeswitch HIGH 7.5
CVE-2021-41145

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.7+
Fix from $1,950 2021-10-25
Gjson HIGH 7.5
CVE-2021-42836

GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.

Fix: 1.9.3+
Fix from $1,950 2021-10-22
Versiondog HIGH 8.1
CVE-2021-38463

The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functio…

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog MEDIUM 6.5
CVE-2021-38465

The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by gene…

Fix: 8.0.0+
Fix from $1,600 2021-10-22
Snudown MEDIUM 6.5
CVE-2021-41168

Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was foun…

Fix: 1.7.0+
Fix from $1,600 2021-10-21
Modern Async HIGH 7.5
CVE-2021-41167

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affe…

Fix: 1.0.4+
Fix from $1,950 2021-10-20
Openjdk MEDIUM 5.3
CVE-2021-35559EPSS 16%

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected ar…

Fix: after 11.50.2
Fix from $1,600 2021-10-20
Junos MEDIUM 6.5
CVE-2021-31365

An Uncontrolled Resource Consumption vulnerability in Juniper Networks Junos OS on EX2300, EX3400 and EX4300 Series platforms allows an adjacent atta…

Fix: 18.1+
Fix from $1,600 2021-10-19
Junos HIGH 7.5
CVE-2021-31368

An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cau…

Fix: 18.1+
Fix from $1,950 2021-10-19
Debian Linux HIGH 7.5
CVE-2021-37136EPSS 6%

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size u…

Fix: 2.2.4 / 4.1.68+
Fix from $1,950 2021-10-19
Debian Linux HIGH 7.5
CVE-2021-37137EPSS 7%

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved…

Fix: 4.1.68 / 12.0.0.4.6+
Fix from $1,950 2021-10-19