Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Linux Kernel MEDIUM 6.8
CVE-2018-20169

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, relate…

Fix: 3.16.63 / 3.18.129+
Fix from $1,600 2018-12-17
Agent HIGH 7.0
CVE-2018-6707

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows…

Fix: after 5.0.6
Fix from $1,950 2018-12-14
Simatic S7 1200 Firmware HIGH 7.5
CVE-2018-13815

A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available…

Fix: 2.6+
Fix from $1,950 2018-12-13
Mupdf MEDIUM 5.5
CVE-2018-19881

In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att cras…

No fix yet
Fix from $1,600 2018-12-06
FreeBSD HIGH 7.5
CVE-2018-17159

In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote u…

Fix: 11.2+
Fix from $1,950 2018-12-04
Libsass MEDIUM 6.5
CVE-2018-19837

In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp allows attackers to cause a denial-of-service resulting f…

Fix: 3.5.5+
Fix from $1,600 2018-12-04
Libsass MEDIUM 6.5
CVE-2018-19838

In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENT_AST_OPERATORS expansion allow attackers to cause a denial-of-service resulting from…

Fix: 3.5.5+
Fix from $1,600 2018-12-04
Hhvm MEDIUM 5.9
CVE-2018-6332

A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources…

Fix: after 3.21.7
Fix from $1,600 2018-12-03
Authoritative HIGH 7.5
CVE-2018-10851EPSS 6%

PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulne…

Fix: after 4.1.4
Fix from $1,950 2018-11-29
Authoritative HIGH 7.5
CVE-2018-14626

PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollutio…

Fix: after 4.1.4
Fix from $1,950 2018-11-29
Node.js HIGH 7.5
CVE-2018-12121EPSS 10%

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many …

Fix: 6.15.0 / 8.14.0+
Fix from $1,950 2018-11-28
Node.js HIGH 7.5
CVE-2018-12122EPSS 41%

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Servic…

Fix: 6.15.1 / 8.14.0+
Fix from $1,950 2018-11-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-14629EPSS 5%

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Samba MEDIUM 5.9
CVE-2018-16853

Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-default MIT Kerb…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Yukiwiki HIGH 7.5
CVE-2018-0700

YukiWiki 2.1.3 and earlier does not process a particular request properly that may allow consumption of large amounts of CPU and memory resources and…

Fix: after 2.1.3
Fix from $1,950 2018-11-15
Rack HIGH 7.5
CVE-2018-16470

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to ente…

Mitigation only
Fix from $1,950 2018-11-13
Emc Recoverpoint HIGH 7.1
CVE-2018-15772

Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulne…

Fix: 5.1.2.1 / 5.2.0.2+
Fix from $1,950 2018-11-13
Spectrum Protect Manager For Virtual Environments Data Protection For Vmware HIGH 7.5
CVE-2018-1786

IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resourc…

Fix: after 8.1.6.0
Fix from $1,950 2018-11-12
Advanced Malware Protection For Endpoints MEDIUM 5.5
CVE-2018-15437

A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Wind…

No fix yet
Fix from $1,600 2018-11-08
Firepower System Software HIGH 7.5
CVE-2018-15443

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured Int…

Mitigation only
Fix from $1,950 2018-11-08
Nginx HIGH 7.5
CVE-2018-16843EPSS 47%

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This iss…

Fix: 1.14.1 / 1.15.6+
Fix from $1,950 2018-11-07
Nginx HIGH 7.5
CVE-2018-16844EPSS 12%

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affect…

Fix: 1.14.1 / 1.15.6+
Fix from $1,950 2018-11-07
Nginx MEDIUM 6.1
CVE-2018-16845EPSS 10%

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker…

Fix: 13.0+
Fix from $1,600 2018-11-07
Debian Linux HIGH 7.5
CVE-2018-16472

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inhe…

Fix: after 1.0.1
Fix from $1,950 2018-11-06
Yi Home Camera Firmware HIGH 7.5
CVE-2018-3935

An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP p…

No fix yet
Fix from $1,950 2018-11-02
Virtualization Host MEDIUM 6.5
CVE-2018-14660

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated…

Fix: after 4.1.4
Fix from $1,600 2018-11-01
Gluster File System MEDIUM 6.5
CVE-2018-14659

The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr…

Fix: after 4.1.4
Fix from $1,600 2018-10-31
Spray Json HIGH 7.5
CVE-2018-18853

Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexit…

Fix: after 1.3.4
Fix from $1,950 2018-10-31
Spray Json HIGH 7.5
CVE-2018-18854

Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexit…

Fix: after 1.3.4
Fix from $1,950 2018-10-31
Merge HIGH 7.5
CVE-2018-16469

The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties…

Fix: 1.2.1+
Fix from $1,950 2018-10-30