Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Bitcoin Sv HIGH 7.5
CVE-2018-1000891

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.

Fix: 0.1.1+
Fix from $1,950 2020-12-23
Bitcoin Sv HIGH 7.5
CVE-2018-1000892

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

Fix: 0.1.1+
Fix from $1,950 2020-12-23
Bitcoin Sv HIGH 7.5
CVE-2018-1000893

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.

Fix: 0.1.1+
Fix from $1,950 2020-12-23
Hue Firmware HIGH 7.5
CVE-2018-7580

Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding…

No fix yet
Fix from $1,950 2020-12-21
Growi HIGH 7.5
CVE-2020-5682

Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and ear…

Fix: 4.1.12 / 4.2.3+
Fix from $1,950 2020-12-16
Go Ethereum MEDIUM 6.5
CVE-2020-26264

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-service vulnerabili…

Fix: 1.9.25+
Fix from $1,600 2020-12-11
GitLab MEDIUM 6.5
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource b…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-11
750 352 Firmware HIGH 7.5
CVE-2020-12516

Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.

Patch available
Fix from $1,950 2020-12-10
Fedora MEDIUM 6.5
CVE-2020-26257

Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or po…

Fix: 1.23.1+
Fix from $1,600 2020-12-09
Fast Csv MEDIUM 6.5
CVE-2020-26256

Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a pos…

Fix: 4.3.6+
Fix from $1,600 2020-12-08
Moodle HIGH 7.5
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, whic…

Fix: 3.5.14 / 3.7.8+
Fix from $1,950 2020-12-08
Btp 2043w Firmware HIGH 7.5
CVE-2020-12524

Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unr…

Mitigation only
Fix from $1,950 2020-12-02
Capi Release HIGH 7.5
CVE-2020-5423

CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can sen…

Fix: 1.101.0 / 15.0.0+
Fix from $1,950 2020-12-02
Debian Linux HIGH 7.5
CVE-2020-27813

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to …

Fix: 1.4.1+
Fix from $1,950 2020-12-02
R00cpu Firmware HIGH 7.5
CVE-2020-16850

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over…

Fix: after 52
Fix from $1,950 2020-11-30
Unbound HIGH 7.5
CVE-2020-10772

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of…

Mitigation only
Fix from $1,950 2020-11-27
Djvalidator HIGH 7.5
CVE-2020-7779

All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, -…

No fix yet
Fix from $1,950 2020-11-26
Crucible HIGH 7.5
CVE-2020-14190

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affec…

Fix: 4.8.4+
Fix from $1,950 2020-11-25
R00cpu Firmware HIGH 7.5
CVE-2020-5668

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) …

Fix: after 51
Fix from $1,950 2020-11-20
Node.js HIGH 7.5
CVE-2020-8277EPSS 54%

A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.…

Fix: 1.16.0 / 9.2.6.0+
Fix from $1,950 2020-11-19
Melsec Iq R00 Firmware HIGH 7.5
CVE-2020-5666EPSS 9%

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/…

Fix: after 51
Fix from $1,950 2020-11-16
Sinumerik 840d Sl Firmware HIGH 7.5
CVE-2020-15783

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (A…

Mitigation only
Fix from $1,950 2020-11-12
Eibport Firmware HIGH 7.5
CVE-2020-24573

BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd compo…

Fix: 3.8.3+
Fix from $1,950 2020-11-12
Express Validators MEDIUM 5.3
CVE-2020-7767

All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invali…

No fix yet
Fix from $1,600 2020-11-11
Android HIGH 7.5
CVE-2020-0441

In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. This could lead to remote den…

Patch available
Fix from $1,950 2020-11-10
Melsec Q Q04udpvcpu Firmware HIGH 7.5
CVE-2020-5652

Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' an…

Mitigation only
Fix from $1,950 2020-11-02
Codemirror HIGH 7.5
CVE-2020-7760EPSS 5%

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expressio…

Fix: 5.58.2 / 11.2.9.0+
Fix from $1,950 2020-10-30
Big Ip Local Traffic Manager HIGH 7.5
CVE-2020-5936

On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel (TMM) process may consume ex…

Fix: 12.1.5.2 / 14.1.2.8+
Fix from $1,950 2020-10-29
Ipad Os MEDIUM 5.5
CVE-2019-8774

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Pars…

Fix: 10.15 / 13.1+
Fix from $1,600 2020-10-27
Safari HIGH 7.5
CVE-2018-4474

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, watchOS 5, Safari 12, iOS 12, …

Fix: 5.0 / 7.7+
Fix from $1,950 2020-10-27