Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Django HIGH 7.5
CVE-2019-14232

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and wo…

Fix: 1.11.23 / 2.1.11+
Fix from $1,950 2019-08-02
Django HIGH 7.5
CVE-2019-14233

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLPars…

Fix: 1.11.23 / 2.1.11+
Fix from $1,950 2019-08-02
Authoritative HIGH 7.5
CVE-2019-10162

A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit…

Fix: 4.0.8 / 4.1.10+
Fix from $1,950 2019-07-30
Imgix MEDIUM 6.5
CVE-2019-13655

Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dim…

Fix: after 2019-06-19
Fix from $1,600 2019-07-29
Electric Fr Configurator2 MEDIUM 5.5
CVE-2019-10972

Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue …

Fix: after 1.16s
Fix from $1,600 2019-07-26
Jsish HIGH 7.5
CVE-2019-1010172

Jsish 2.4.84 2.0484 is affected by: Uncontrolled Resource Consumption. The impact is: denial of service. The component is: function jsiValueGetString…

Mitigation only
Fix from $1,950 2019-07-25
Metadataextractor HIGH 7.5
CVE-2019-14262

MetadataExtractor 2.1.0 allows stack consumption.

Patch available
Fix from $1,950 2019-07-25
Lodash MEDIUM 6.5
CVE-2019-1010266

lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler.…

Fix: 4.17.11+
Fix from $1,600 2019-07-17
Junos MEDIUM 6.5
CVE-2019-0046

A vulnerability in the pfe-chassisd Chassis Manager (CMLC) daemon of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) …

Patch available
Fix from $1,600 2019-07-11
Asa 5506 X Firmware HIGH 8.6
CVE-2019-1873

A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could al…

Mitigation only
Fix from $1,950 2019-07-10
Bravia Firmware HIGH 7.5
CVE-2019-11890

Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wired or Wi-Fi…

No fix yet
Fix from $1,950 2019-07-09
Linux Kernel HIGH 7.5
CVE-2019-11478EPSS 95%

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling cer…

Fix: 4.4.182 / 4.9.182+
Fix from $1,950 2019-06-19
Msm8909w Firmware CRITICAL 9.8
CVE-2019-2259

Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdragon Compute, Snapdrag…

Mitigation only
Fix from $2,300 2019-06-14
Mdm9206 Firmware CRITICAL 9.8
CVE-2018-11936

Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads to out of bound memory access…

Mitigation only
Fix from $2,300 2019-05-24
Qj71e71 100 Firmware HIGH 7.5
CVE-2019-10977

In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against …

Fix: after 20121
Fix from $1,950 2019-05-23
Somachine Basic HIGH 7.5
CVE-2018-7821

An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0…

Fix: 1.10.0.0+
Fix from $1,950 2019-05-22
Enterprise Linux HIGH 7.5
CVE-2019-0820EPSS 6%

A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial…

Patch available
Fix from $1,950 2019-05-16
GitLab HIGH 7.5
CVE-2019-10113

An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent G…

Fix: 11.7.8 / 11.8.4+
Fix from $1,950 2019-05-16
Sf302 08pp Firmware HIGH 8.6
CVE-2019-1814

A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an un…

Fix: 1.4.10.6+
Fix from $1,950 2019-05-16
Sinamics Perfect Harmony Gh180 With Nxg I Control Mlfb 6sr2 Firmware HIGH 7.5
CVE-2019-6578

A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with opti…

Mitigation only
Fix from $1,950 2019-05-14
Hub 3.0 Firmware HIGH 7.5
CVE-2018-19037

On Virgin Media wireless router 3.0 hub devices, the web interface is vulnerable to denial of service. When POST requests are sent and keep the conne…

No fix yet
Fix from $1,950 2019-05-13
Imageworsener MEDIUM 6.5
CVE-2017-12804

The iwgif_init_screen function in imagew-gif.c:510 in ImageWorsener 1.3.2 allows remote attackers to cause a denial of service (hmemory exhaustion) v…

No fix yet
Fix from $1,600 2019-05-09
Imagemagick HIGH 7.5
CVE-2017-12805

In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function ReadTIFFImage, which allows attackers to cause a denial of servic…

No fix yet
Fix from $1,950 2019-05-09
Imagemagick HIGH 7.5
CVE-2017-12806

In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function format8BIM, which allows attackers to cause a denial of service.

No fix yet
Fix from $1,950 2019-05-09
Fl Switch 3005 Firmware HIGH 7.5
CVE-2018-13994

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 conn…

Fix: after 1.34
Fix from $1,950 2019-05-07
Secure Firewall Threat Defense HIGH 8.6
CVE-2019-1703

A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series …

Fix: 6.2.3.12+
Fix from $1,950 2019-05-03
Secure Firewall Threat Defense HIGH 7.5
CVE-2019-1704

Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software c…

Fix: 6.2.3.12+
Fix from $1,950 2019-05-03
Secure Firewall Management Center HIGH 7.4
CVE-2019-1696

Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software c…

Fix: 6.2.3.12+
Fix from $1,950 2019-05-03
Adaptive Security Appliance Software HIGH 8.6
CVE-2018-15388

A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software cou…

Fix: 6.2.3.12 / 9.4.4.34+
Fix from $1,950 2019-05-03
Compactlogix 5370 L1 Firmware CRITICAL 9.8
CVE-2019-10952EPSS 10%

An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based…

Fix: after 30.014
Fix from $2,300 2019-05-01