Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Acrobat Dc MEDIUM 5.5
CVE-2020-9703

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a stack…

Fix: after 20.009.20074
Fix from $1,600 2020-08-19
GitLab MEDIUM 6.5
CVE-2020-13281

For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature

Fix: 13.0.12 / 13.1.6+
Fix from $1,600 2020-08-13
GitLab MEDIUM 6.5
CVE-2020-13280

For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.

Fix: 13.0.12 / 13.1.6+
Fix from $1,600 2020-08-13
Desktop MEDIUM 5.5
CVE-2020-8229

A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.

Fix: 2.6.5+
Fix from $1,600 2020-08-10
Whoopsie MEDIUM 5.5
CVE-2020-11937

In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource ex…

No fix yet
Fix from $1,600 2020-08-06
Etcd HIGH 7.7
CVE-2020-15114

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is pos…

Fix: 3.3.23 / 3.4.10+
Fix from $1,950 2020-08-06
Series 30i Firmware MEDIUM 5.3
CVE-2020-12739

A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affect…

Mitigation only
Fix from $1,600 2020-08-03
Fastify MEDIUM 6.5
CVE-2020-8192

A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the all…

No fix yet
Fix from $1,600 2020-07-30
Connect Secure MEDIUM 6.5
CVE-2020-8220

A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the ad…

Fix: after 9.0
Fix from $1,600 2020-07-30
Jpeg Js MEDIUM 5.5
CVE-2020-8175

Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG ima…

Fix: 0.4.0+
Fix from $1,600 2020-07-24
Amq MEDIUM 6.5
CVE-2020-14297

A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated ov…

Fix: 4.0.34+
Fix from $1,600 2020-07-24
Kubernetes MEDIUM 5.5
CVE-2020-8557

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its …

Fix: 1.16.13 / 1.17.9+
Fix from $1,600 2020-07-23
Sd Wan Firmware MEDIUM 6.5
CVE-2020-3372

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to consume exces…

Fix: 19.2.3 / 20.1.12+
Fix from $1,600 2020-07-16
Sd Wan Firmware HIGH 8.6
CVE-2020-3351

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The v…

Fix: 17.2.7 / 18.3.0+
Fix from $1,950 2020-07-16
Simatic S7 200 Smart Sr Cpu Firmware HIGH 7.5
CVE-2020-7584

A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly handle large…

Fix: 2.5.1+
Fix from $1,950 2020-07-14
Opcenter Execution Discrete HIGH 8.2
CVE-2020-7587

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcent…

Fix: 2.6 / 3.2+
Fix from $1,950 2020-07-14
Fedora HIGH 7.5
CVE-2020-10745

A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows…

Fix: 4.10.17 / 4.11.11+
Fix from $1,950 2020-07-07
Debian Linux HIGH 8.8
CVE-2020-15565

An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges…

Fix: after 4.13.1
Fix from $1,950 2020-07-07
Rails MEDIUM 6.5
CVE-2020-8185

A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in pro…

Fix: 6.0.3.2+
Fix from $1,600 2020-07-02
Envoy HIGH 7.5
CVE-2020-8663

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.

Fix: after 1.14.2
Fix from $1,950 2020-07-01
Envoy HIGH 7.5
CVE-2020-12603

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i…

Fix: after 1.12.4
Fix from $1,950 2020-07-01
Cpu Module Logging Configuration Tool HIGH 7.5
CVE-2020-5603

Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and…

Fix: after 1.590q
Fix from $1,950 2020-06-30
Acrobat Dc MEDIUM 5.5
CVE-2020-9611

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier …

Fix: 15.006.30518 / 17.011.30166+
Fix from $1,600 2020-06-25
Mattermost Server HIGH 7.5
CVE-2015-9548

An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compress…

Fix: 1.2.0+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2018-21250

An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consump…

Fix: 4.10.4 / 5.1.2+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20858

An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters…

Fix: 5.15.0+
Fix from $1,950 2020-06-19
Fedora CRITICAL 9.8
CVE-2017-9104

An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.

Fix: 1.5.2+
Fix from $2,300 2020-06-18
Easergy T300 Firmware HIGH 7.5
CVE-2020-7507

A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Debian Linux HIGH 7.1
CVE-2020-14152

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing exces…

Fix: 9d+
Fix from $1,950 2020-06-15
Openstack Mistral MEDIUM 6.5
CVE-2018-16848

A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow d…

Fix: after 7.0.3
Fix from $1,600 2020-06-15