Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Junos MEDIUM 6.5
CVE-2020-1600

In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon…

Mitigation only
Fix from $1,600 2020-01-15
The Update Framework MEDIUM 5.3
CVE-2020-6173

TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.

Fix: after 0.12.1
Fix from $1,600 2020-01-14
GitLab MEDIUM 5.3
CVE-2019-20146

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.

Fix: after 12.6.0
Fix from $1,600 2020-01-13
Publify HIGH 7.5
CVE-2014-3211

Publify before 8.0.1 is vulnerable to a Denial of Service attack

Fix: 8.0.1+
Fix from $1,950 2020-01-09
Bss Continuty Cms HIGH 7.5
CVE-2014-3447

BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability

No fix yet
Fix from $1,950 2020-01-09
Ecstatic HIGH 7.5
CVE-2019-10775

ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.

No fix yet
Fix from $1,950 2020-01-02
Ezxml MEDIUM 6.5
CVE-2019-20201

An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory…

Fix: after 0.8.6
Fix from $1,600 2019-12-31
Fedora HIGH 7.5
CVE-2019-20176

In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.

Patch available
Fix from $1,950 2019-12-31
Fedora HIGH 7.5
CVE-2012-5645

A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a …

Fix: 2.3.4+
Fix from $1,950 2019-12-30
Linux Kernel MEDIUM 5.5
CVE-2011-1474

A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.patch, and 2.6.37.4-test14.patch…

Mitigation only
Fix from $1,600 2019-12-26
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6683

On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose I…

Fix: 14.0.1.1 / 14.1.2.3+
Fix from $1,950 2019-12-23
Big Ip Application Security Manager HIGH 7.5
CVE-2019-6682

On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP ASM system may consume excessive resour…

Fix: 13.1.3.2 / 14.1.2.3+
Fix from $1,950 2019-12-23
Linux Kernel MEDIUM 5.5
CVE-2019-19922

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of se…

Fix: 5.3.9+
Fix from $1,600 2019-12-22
GitLab MEDIUM 6.5
CVE-2019-15584

A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take dow…

Fix: 12.1.10 / 12.2.6+
Fix from $1,600 2019-12-20
Build Failure Analyzer MEDIUM 6.5
CVE-2019-16555

A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way that wasn't interruptible, allo…

Fix: after 1.24.1
Fix from $1,600 2019-12-17
Qpid Cpp HIGH 7.5
CVE-2014-0212

qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors

Mitigation only
Fix from $1,950 2019-12-13
Spamassassin HIGH 7.5
CVE-2019-12420EPSS 7%

In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r…

Fix: 3.4.3+
Fix from $1,950 2019-12-12
Airlive Poe2600hd Firmware HIGH 7.5
CVE-2013-3691

AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.

No fix yet
Fix from $1,950 2019-12-11
Katello HIGH 7.5
CVE-2013-4120

Katello has a Denial of Service vulnerability in API OAuth authentication

No fix yet
Fix from $1,950 2019-12-10
Ie Sw Pl09m 5gc 4gt Firmware MEDIUM 6.5
CVE-2019-16671

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 dev…

Fix: after 3.4.4
Fix from $1,600 2019-12-06
Linux Kernel CRITICAL 9.8
CVE-2019-14901EPSS 17%

A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows…

Fix: 3.16.83 / 4.4.217+
Fix from $2,300 2019-11-29
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6667

On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may con…

Fix: after 15.0.1
Fix from $1,950 2019-11-27
Fedora HIGH 8.8
CVE-2019-14867EPSS 7%

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the interna…

Fix: 4.6.7 / 4.7.4+
Fix from $1,950 2019-11-27
Fedora HIGH 7.5
CVE-2019-6477

With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without…

Fix: after 9.15.5
Fix from $1,950 2019-11-26
Debian Linux HIGH 7.5
CVE-2011-4082

A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remot…

Fix: 0.9.8+
Fix from $1,950 2019-11-26
Powassent MEDIUM 5.5
CVE-2019-16764

The use of `String.to_atom/1` in PowAssent is susceptible to denial of service attacks. In `PowAssent.Phoenix.AuthorizationController` a value is fet…

Fix: 0.4.4+
Fix from $1,600 2019-11-25
Fedora HIGH 7.5
CVE-2019-11287

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.1…

Fix: 1.16.7 / 1.17.4+
Fix from $1,950 2019-11-23
GitLab MEDIUM 6.5
CVE-2019-15593

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Is…

Patch available
Fix from $1,600 2019-11-22
Pyxml HIGH 7.5
CVE-2012-0877

PyXML: Hash table collisions CPU usage Denial of Service

Mitigation only
Fix from $1,950 2019-11-22
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6660

On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lea…

Fix: 13.1.3 / 14.0.1.1+
Fix from $1,950 2019-11-15