Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Iks G6824a Firmware MEDIUM 6.5
CVE-2019-6559

Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch to crash.

Fix: after 4.5
Fix from $1,600 2019-03-05
Debian Linux HIGH 7.5
CVE-2018-5819

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust availa…

Fix: 0.19.1+
Fix from $1,950 2019-02-20
Libexif HIGH 7.5
CVE-2018-20030

An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU…

Patch available
Fix from $1,950 2019-02-20
Wtcms HIGH 7.5
CVE-2019-8909

An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the v…

No fix yet
Fix from $1,950 2019-02-18
Airos HIGH 7.5
CVE-2017-0938EPSS 21%

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attack…

Fix: 1.9.7 / 6.0.7+
Fix from $1,950 2019-02-12
Web Security Appliance MEDIUM 5.8
CVE-2019-1672

A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remot…

Mitigation only
Fix from $1,600 2019-02-08
Q03udvcpu Firmware HIGH 7.5
CVE-2019-6535

Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/1…

Fix: after 20081
Fix from $1,950 2019-02-05
Mpath HIGH 7.5
CVE-2018-16490

A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

Fix: 0.5.1+
Fix from $1,950 2019-02-01
Node.extend CRITICAL 9.8
CVE-2018-16491

A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.proto…

Fix: 1.1.7 / 2.0.1+
Fix from $2,300 2019-02-01
Extend CRITICAL 9.8
CVE-2018-16492

A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.pro…

Fix: 2.0.2 / 3.0.2+
Fix from $2,300 2019-02-01
Defaults Deep CRITICAL 9.8
CVE-2018-16486

A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.

Fix: after 0.2.4
Fix from $2,300 2019-02-01
Lodash MEDIUM 5.6
CVE-2018-16487

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or…

Fix: 4.17.11+
Fix from $1,600 2019-02-01
Just Extend CRITICAL 9.8
CVE-2018-16489

A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functio…

Fix: 4.0.0+
Fix from $2,300 2019-02-01
HTTP Server MEDIUM 5.3
CVE-2018-17189EPSS 20%

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unn…

Mitigation only
Fix from $1,600 2019-01-30
Vitro HIGH 7.5
CVE-2019-6986

SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression de…

Patch available
Fix from $1,950 2019-01-28
Iot Field Network Director HIGH 7.5
CVE-2019-1644

A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to …

Mitigation only
Fix from $1,950 2019-01-23
Bind MEDIUM 5.9
CVE-2017-3140EPSS 12%

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop …

Fix: after 9.11.1
Fix from $1,600 2019-01-16
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3144EPSS 73%

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors availabl…

Mitigation only
Fix from $1,950 2019-01-16
Wangle MEDIUM 5.9
CVE-2019-3554

Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against…

Fix: 2019.01.14.00+
Fix from $1,600 2019-01-15
Asr 900 Series Software MEDIUM 5.8
CVE-2018-15464

A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote attacker to cause a partial den…

Mitigation only
Fix from $1,600 2019-01-11
Proxygen HIGH 7.5
CVE-2018-6346

A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Pr…

Fix: 2018.12.31.00+
Fix from $1,950 2018-12-31
Proxygen HIGH 7.5
CVE-2018-6347

An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.1…

Fix: 2018.12.31.00+
Fix from $1,950 2018-12-31
Hhvm HIGH 7.5
CVE-2018-6335

A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affec…

Fix: after 3.21.10
Fix from $1,950 2018-12-31
Libxsmm MEDIUM 6.5
CVE-2018-20543

There is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXSMM 1.10 that will cause a den…

No fix yet
Fix from $1,600 2018-12-28
Bento4 MEDIUM 6.5
CVE-2018-20502

An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_Hvcc…

No fix yet
Fix from $1,600 2018-12-26
Qt MEDIUM 6.5
CVE-2018-19871

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

Fix: 5.11.3+
Fix from $1,600 2018-12-26
Epson Workforce Wf 2861 Firmware MEDIUM 5.9
CVE-2018-18960

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. They use SNMP to find certain devices on the …

No fix yet
Fix from $1,600 2018-12-24
Kerberised Netcat HIGH 7.5
CVE-2017-9732

The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remote…

Fix: 1.11-1+
Fix from $1,950 2018-12-20
Pykmip MEDIUM 6.5
CVE-2018-1000872

OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in Py…

Fix: 0.8.0+
Fix from $1,600 2018-12-20
Bento4 MEDIUM 6.5
CVE-2018-20186

An issue was discovered in Bento4 1.5.1-627. AP4_Sample::ReadData in Core/Ap4Sample.cpp allows attackers to trigger an attempted excessive memory all…

No fix yet
Fix from $1,600 2018-12-17