Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Junos HIGH 7.5
CVE-2019-0059

A memory leak vulnerability in the of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending specif…

Mitigation only
Fix from $1,950 2019-10-09
Envoy HIGH 7.5
CVE-2019-15226EPSS 65%

Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays…

Patch available
Fix from $1,950 2019-10-09
Fon2601e Se Firmware HIGH 7.5
CVE-2019-6015

FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue where they may behave as open …

Fix: after 1.1.7
Fix from $1,950 2019-10-04
Adaptive Security Appliance Software HIGH 8.6
CVE-2019-15256

A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat…

Fix: 6.2.3.11 / 6.3.0.2+
Fix from $1,950 2019-10-02
Ic3000 Industrial Compute Gateway Firmware MEDIUM 6.5
CVE-2019-12714

A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cau…

Fix: 1.1.1+
Fix from $1,600 2019-10-02
Adaptive Security Appliance HIGH 7.5
CVE-2019-12698

A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could all…

Fix: 6.2.3.15 / 6.3.0.5+
Fix from $1,950 2019-10-02
Firepower 9300 Firmware MEDIUM 6.5
CVE-2019-12700

A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepo…

Fix: 2.3.1.155 / 2.6.1.131+
Fix from $1,600 2019-10-02
Android MEDIUM 6.5
CVE-2019-9349

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2019-09-27
Ios Xe HIGH 7.5
CVE-2019-12659

A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. T…

Mitigation only
Fix from $1,950 2019-09-25
Ios Xe HIGH 7.5
CVE-2019-12658

A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesy…

Mitigation only
Fix from $1,950 2019-09-25
Libav MEDIUM 6.5
CVE-2019-9717

In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_t…

Fix: after 12.3
Fix from $1,600 2019-09-19
Cognos Analytics HIGH 7.5
CVE-2019-4183

IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send specially crafted requests tha…

Patch available
Fix from $1,950 2019-09-17
Nx Os HIGH 7.5
CVE-2019-1967

A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial …

Mitigation only
Fix from $1,950 2019-08-30
Hg100 Firmware HIGH 7.5
CVE-2019-11060

The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause …

Fix: after 1.05.12
Fix from $1,950 2019-08-29
Nx Os HIGH 7.7
CVE-2019-1965

A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH p…

Fix: 6.2 / 7.0+
Fix from $1,950 2019-08-28
Asn1 Der HIGH 7.5
CVE-2019-15549

An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplying a large value in a length f…

Fix: 0.6.2+
Fix from $1,950 2019-08-26
Linux Kernel HIGH 7.5
CVE-2019-15538

An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on acc…

Fix: 4.9.191 / 4.14.141+
Fix from $1,950 2019-08-25
Set Value CRITICAL 9.8
CVE-2019-10747

set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying proper…

Fix: 2.0.1 / 3.0.1+
Fix from $2,300 2019-08-23
Deeply CRITICAL 9.8
CVE-2019-10750

deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties o…

Fix: 3.1.0+
Fix from $2,300 2019-08-23
Mq MEDIUM 5.5
CVE-2019-4049

IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill up the disk space of the unde…

Fix: after 9.1.1
Fix from $1,600 2019-08-20
Homematic Ccu3 Firmware HIGH 8.2
CVE-2019-9583

eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected ve…

No fix yet
Fix from $1,950 2019-08-14
Traffic Server HIGH 7.5
CVE-2019-9518EPSS 25%

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9511EPSS 60%

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9512EPSS 83%

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/…

Fix: 8.16.1 / 10.16.3+
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9513EPSS 82%

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request strea…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9514EPSS 83%

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9515EPSS 87%

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server MEDIUM 6.5
CVE-2019-9516EPSS 56%

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with …

Fix: after 8.0.3
Fix from $1,600 2019-08-13
HTTP Server HIGH 7.5
CVE-2019-9517EPSS 28%

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th…

Fix: 2.4.40+
Fix from $1,950 2019-08-13
Scalance X 200 Firmware HIGH 8.6
CVE-2019-10942

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch fam…

Mitigation only
Fix from $1,950 2019-08-13