Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Android MEDIUM 6.5
CVE-2020-0173

In Parse_lins of eas_mdls.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with…

Patch available
Fix from $1,600 2020-06-11
Indy Node HIGH 7.5
CVE-2020-11090

In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can b…

Mitigation only
Fix from $1,950 2020-06-11
Melsec Iq R00cpu Firmware HIGH 7.5
CVE-2020-13238

Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthenticated crafted packet over …

Fix: after 39
Fix from $1,950 2020-06-10
Mqtt HIGH 7.5
CVE-2020-13849

The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attacke…

Mitigation only
Fix from $1,950 2020-06-04
Url Regex HIGH 7.5
CVE-2020-7661

all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a…

No fix yet
Fix from $1,950 2020-06-04
Phantompdf HIGH 7.5
CVE-2018-21238

An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.

Fix: 8.3.7+
Fix from $1,950 2020-06-04
Phantompdf HIGH 7.5
CVE-2018-21240

An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.

Fix: 9.2+
Fix from $1,950 2020-06-04
Phantompdf HIGH 7.5
CVE-2020-13815

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.

Fix: 9.7.1+
Fix from $1,950 2020-06-04
Phantompdf HIGH 7.5
CVE-2020-13809

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in the content stream.

Fix: 9.7.2+
Fix from $1,950 2020-06-04
Debian Linux HIGH 7.5
CVE-2020-11080EPSS 5%

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a mal…

Fix: 1.41.0 / 10.21.0+
Fix from $1,950 2020-06-03
Ios Xe HIGH 8.6
CVE-2020-3203

A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless Controllers that are running…

Patch available
Fix from $1,950 2020-06-03
Linux Kernel MEDIUM 5.5
CVE-2019-20812

An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet.c can result in a denial of …

Fix: 5.4.7+
Fix from $1,600 2020-06-03
Lexiglot HIGH 7.5
CVE-2014-8937

Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.

Fix: after 2014-11-20
Fix from $1,950 2020-06-01
Jerryscript HIGH 7.5
CVE-2020-13623

JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation.

No fix yet
Fix from $1,950 2020-05-27
PHP MEDIUM 5.3
CVE-2019-11048EPSS 6%

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or …

Fix: 7.2.31 / 7.3.18+
Fix from $1,600 2020-05-20
Fedora HIGH 7.5
CVE-2020-10995

PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has b…

Fix: after 4.3.0
Fix from $1,950 2020-05-19
Debian Linux HIGH 7.5
CVE-2020-12662

Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NS…

Fix: 1.10.1+
Fix from $1,950 2020-05-19
Debian Linux HIGH 8.6
CVE-2020-8616EPSS 11%

A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, thro…

Fix: after 9.17.1
Fix from $1,950 2020-05-19
Knot Resolver HIGH 7.5
CVE-2020-12667

Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This …

Fix: 5.1.1+
Fix from $1,950 2020-05-19
Adaptive Security Appliance Software HIGH 7.4
CVE-2020-3334

A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software fo…

Fix: 6.6.0 / 9.10.1.37+
Fix from $1,950 2020-05-06
Adaptive Security Appliance HIGH 7.5
CVE-2020-3303

A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat…

Fix: 6.3.0.5 / 6.4.0.6+
Fix from $1,950 2020-05-06
Adaptive Security Appliance HIGH 7.5
CVE-2020-3305

A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firep…

Fix: 6.3.0.5 / 6.4.0.6+
Fix from $1,950 2020-05-06
Adaptive Security Appliance HIGH 7.5
CVE-2020-3306

A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow …

Fix: 6.3.0.5 / 6.4.0.4+
Fix from $1,950 2020-05-06
Secure Firewall Threat Defense HIGH 8.6
CVE-2020-3189

A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,950 2020-05-06
Secure Firewall Threat Defense HIGH 7.5
CVE-2020-3195

A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat …

Fix: 6.4.0.9 / 6.5.0.5+
Fix from $1,950 2020-05-06
Secure Firewall Threat Defense HIGH 8.6
CVE-2020-3196

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisc…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-05-06
Secure Firewall Threat Defense HIGH 7.5
CVE-2020-3254

Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Fire…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-05-06
Secure Firewall Threat Defense HIGH 7.5
CVE-2020-3255

A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attack…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-05-06
Traffic Server HIGH 7.5
CVE-2020-9481

Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

Fix: after 8.0.6
Fix from $1,950 2020-04-27
Enterprise Linux MEDIUM 5.3
CVE-2020-1722

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password has…

Fix: after 4.8.0
Fix from $1,600 2020-04-27