Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Cr Ir 357 Fcr Carbon X Firmware HIGH 7.5
CVE-2019-10948

Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptible to a …

Mitigation only
Fix from $1,950 2019-04-30
Openshift Container Platform HIGH 7.5
CVE-2019-2602

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…

Patch available
Fix from $1,950 2019-04-23
Imagemagick MEDIUM 6.5
CVE-2019-11470

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by craftin…

Patch available
Fix from $1,600 2019-04-23
Linux Kernel MEDIUM 5.9
CVE-2013-7470

cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial…

Fix: 3.11.7+
Fix from $1,600 2019-04-23
Owasp Modsecurity Core Rule Set MEDIUM 5.3
CVE-2019-11387

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf allows remote attacke…

Fix: after 3.1.0
Fix from $1,600 2019-04-21
Owasp Modsecurity Core Rule Set MEDIUM 5.3
CVE-2019-11388

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf allows remote attacker…

Fix: after 3.1.0
Fix from $1,600 2019-04-21
Owasp Modsecurity Core Rule Set MEDIUM 5.3
CVE-2019-11389

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attacker…

Fix: after 3.1.0
Fix from $1,600 2019-04-21
Owasp Modsecurity Core Rule Set MEDIUM 5.3
CVE-2019-11390

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attacker…

Fix: after 3.1.0
Fix from $1,600 2019-04-21
Owasp Modsecurity Core Rule Set MEDIUM 5.3
CVE-2019-11391

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attacker…

Fix: after 3.1.0
Fix from $1,600 2019-04-21
Ubuntu Linux MEDIUM 5.5
CVE-2018-16878

A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead…

Fix: after 2.0.1
Fix from $1,600 2019-04-18
GitLab HIGH 7.5
CVE-2019-9220

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontro…

Fix: 11.6.10 / 11.7.6+
Fix from $1,950 2019-04-17
Pm554 Tp Eth Firmware HIGH 7.5
CVE-2019-10953

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers …

Fix: 1.10.0.0+
Fix from $1,950 2019-04-17
Junos HIGH 7.5
CVE-2019-0031

Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Junos OS device using the jdhcp…

Fix: 17.4r2 / 18.1r2+
Fix from $1,950 2019-04-10
Junos HIGH 7.5
CVE-2019-0033

A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high CPU condition leading to a D…

Fix: 12.1x46-d71 / 12.3x48-d50+
Fix from $1,950 2019-04-10
Junos MEDIUM 6.5
CVE-2019-0038

Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition du…

Mitigation only
Fix from $1,600 2019-04-10
Tomcat HIGH 7.5
CVE-2019-0199EPSS 73%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also…

Fix: after 9.0.14
Fix from $1,950 2019-04-10
Powerflex 525 Ac Drives Firmware CRITICAL 9.8
CVE-2018-19282EPSS 6%

Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial P…

Fix: after 5.001
Fix from $2,300 2019-04-04
Safari MEDIUM 6.5
CVE-2018-4409

A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, i…

Fix: 7.8 / 12.0.1+
Fix from $1,600 2019-04-03
Websphere Application Server MEDIUM 6.5
CVE-2019-4080

IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter pa…

Fix: after 9.0.0.10
Fix from $1,600 2019-04-02
Ubuntu Linux MEDIUM 6.5
CVE-2018-3979

A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader e…

No fix yet
Fix from $1,600 2019-04-01
Mailplus Server HIGH 7.5
CVE-2018-13296

Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct…

Fix: 2.0.5-0606+
Fix from $1,950 2019-04-01
Ios Xe HIGH 8.6
CVE-2019-1737

A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE software could allow an unauthen…

Patch available
Fix from $1,950 2019-03-27
Fedora HIGH 7.5
CVE-2018-12545EPSS 5%

In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs fra…

Patch available
Fix from $1,950 2019-03-27
Rails HIGH 7.5
CVE-2019-5419EPSS 9%

There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept hea…

Fix: 4.2.11.1 / 5.0.7.2+
Fix from $1,950 2019-03-27
Websphere Application Server HIGH 7.5
CVE-2019-4046

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remot…

Fix: 19.0.0.4+
Fix from $1,950 2019-03-25
Linux Kernel MEDIUM 6.5
CVE-2019-3874

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of …

Fix: after 4.18.20
Fix from $1,600 2019-03-25
Colossuscoinxt HIGH 7.5
CVE-2018-19158

ColossusCoinXT through 1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires…

Fix: after 1.0.5
Fix from $1,950 2019-03-21
Fedora HIGH 7.5
CVE-2018-18898

The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic comp…

Fix: after 4.4.0
Fix from $1,950 2019-03-21
Iotivity CRITICAL 9.1
CVE-2019-9750

In IoTivity through 1.3.1, the CoAP server interface can be used for Distributed Denial of Service attacks using source IP address spoofing and UDP-b…

Fix: after 1.3.1
Fix from $2,300 2019-03-13
Xpdfreader HIGH 7.8
CVE-2019-9587

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for examp…

No fix yet
Fix from $1,950 2019-03-06