Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Fedora MEDIUM 5.5
CVE-2021-26260

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this …

Fix: 3.0.1+
Fix from $1,600 2021-06-08
Machine Config Operator MEDIUM 6.5
CVE-2020-1750

A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memo…

Fix: 4.2.36 / 4.3.25+
Fix from $1,600 2021-06-07
Video Surveillance 7530pd Firmware MEDIUM 6.5
CVE-2021-1563

Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance …

Fix: 2.12.3+
Fix from $1,600 2021-06-04
Video Surveillance 7530pd Firmware MEDIUM 6.5
CVE-2021-1564

Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance …

Fix: 2.12.3+
Fix from $1,600 2021-06-04
Glob Parent HIGH 7.5
CVE-2020-28469

This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.

Fix: 5.1.2+
Fix from $1,950 2021-06-03
Jboss Remoting MEDIUM 5.9
CVE-2020-35510

A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB…

Fix: 5.0.20+
Fix from $1,600 2021-06-02
Xnio MEDIUM 5.9
CVE-2020-14340

A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection c…

Fix: 3.7.9 / 3.8.2+
Fix from $1,600 2021-06-02
Integration Camel K HIGH 7.5
CVE-2020-14326

A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with…

Fix: 4.5.6+
Fix from $1,950 2021-06-02
Debian Linux HIGH 7.5
CVE-2021-33623

The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the …

Fix: 3.0.1 / 4.0.1+
Fix from $1,950 2021-05-28
Enterprise Linux MEDIUM 5.3
CVE-2021-20201

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumpt…

Fix: 0.14.92+
Fix from $1,600 2021-05-28
Libzmq HIGH 7.5
CVE-2021-20237

An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauth…

Fix: 4.3.3+
Fix from $1,950 2021-05-28
Certification HIGH 7.5
CVE-2018-10868

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user …

Mitigation only
Fix from $1,950 2021-05-26
Linux Kernel MEDIUM 5.5
CVE-2020-25673

A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.

Fix: 5.3.18+
Fix from $1,600 2021-05-26
Ws MEDIUM 5.3
CVE-2021-32640

ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to…

Fix: 6.2.2 / 7.4.6+
Fix from $1,600 2021-05-25
Enterprise Linux HIGH 7.5
CVE-2020-36332

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from th…

Fix: 1.0.1+
Fix from $1,950 2021-05-21
Fedora HIGH 7.5
CVE-2021-20718

mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.

Fix: 21.3+
Fix from $1,950 2021-05-20
Fedora MEDIUM 5.5
CVE-2021-32617

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (…

Fix: 0.27.4+
Fix from $1,600 2021-05-17
Cap\/prx Firmware MEDIUM 6.5
CVE-2021-32455

SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of service condition on the device. A…

Mitigation only
Fix from $1,600 2021-05-17
Protonmail HIGH 7.5
CVE-2021-32816

ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Client before version 3.16.60 has …

Fix: 3.16.60+
Fix from $1,950 2021-05-14
Graphhopper MEDIUM 6.5
CVE-2021-29506

GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vu…

Fix: 2.4+
Fix from $1,600 2021-05-13
Kibana MEDIUM 6.5
CVE-2021-22139

Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the r…

Fix: 7.12.1+
Fix from $1,600 2021-05-13
Debian Linux HIGH 7.5
CVE-2021-32918

An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memo…

Fix: 0.11.9+
Fix from $1,950 2021-05-13
Simatic Wincc Runtime Advanced HIGH 7.5
CVE-2021-27385

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…

Fix: 15.1 / 16+
Fix from $1,950 2021-05-12
Simatic Net Cp 343 1 Advanced Firmware HIGH 7.5
CVE-2020-25242

A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS …

Mitigation only
Fix from $1,950 2021-05-12
Puma HIGH 7.5
CVE-2021-29509

Puma is a concurrent HTTP 1.1 server for Ruby/Rack applications. The fix for CVE-2019-16770 was incomplete. The original fix only protected existing …

Fix: 4.3.8 / 5.3.1+
Fix from $1,950 2021-05-11
Fedora MEDIUM 5.3
CVE-2021-29471

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.33.2+
Fix from $1,600 2021-05-11
Intellij Idea HIGH 7.5
CVE-2021-30504

In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.

Fix: 2021.1+
Fix from $1,950 2021-05-11
Hapi Fhir MEDIUM 5.3
CVE-2021-32053

JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests…

Fix: 5.4.0+
Fix from $1,600 2021-05-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23011

On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.…

Fix: 11.6.5.3 / 12.1.6+
Fix from $1,950 2021-05-10
Fedora MEDIUM 5.3
CVE-2021-21419

Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. …

Fix: 0.31.0+
Fix from $1,600 2021-05-07