Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Sd 210 Firmware HIGH 7.5
CVE-2018-11828

When FW tries to get random mac address generated from new SW RNG and ADC values read are constant then DUT get struck in loop while trying to get ra…

Mitigation only
Fix from $1,950 2018-10-26
Mdm9206 Firmware MEDIUM 5.5
CVE-2017-18299

Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon…

Mitigation only
Fix from $1,600 2018-10-23
Aironet Access Points MEDIUM 6.8
CVE-2018-0381

A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device …

Mitigation only
Fix from $1,600 2018-10-17
Access Points HIGH 7.4
CVE-2018-0441

A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacke…

Fix: 8.3.140.0 / 8.5.110.0+
Fix from $1,950 2018-10-17
Fcj Firmware HIGH 7.5
CVE-2018-17898

Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhausti…

Mitigation only
Fix from $1,950 2018-10-12
Junos MEDIUM 5.3
CVE-2018-0061

A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect sys…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 6.5
CVE-2018-0063

A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust …

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 6.5
CVE-2018-0054

On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the management interface (fxp0) can ca…

Mitigation only
Fix from $1,600 2018-10-10
Junos HIGH 7.5
CVE-2018-0048

A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker…

Mitigation only
Fix from $1,950 2018-10-10
Simatic Et 200sp Firmware HIGH 7.5
CVE-2018-13805

A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All…

Fix: 2.5+
Fix from $1,950 2018-10-10
Unity Connection MEDIUM 6.8
CVE-2018-15396

A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk uti…

Mitigation only
Fix from $1,600 2018-10-05
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2018-15399

A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could …

Mitigation only
Fix from $1,600 2018-10-05
Firepower Threat Defense HIGH 7.5
CVE-2018-15383

A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defen…

Mitigation only
Fix from $1,950 2018-10-05
iOS HIGH 8.6
CVE-2018-15377

A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS X…

Mitigation only
Fix from $1,950 2018-10-05
Ios Xe HIGH 7.4
CVE-2018-0471

A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adja…

Mitigation only
Fix from $1,950 2018-10-05
Binutils MEDIUM 5.5
CVE-2018-17985

An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cp…

Mitigation only
Fix from $1,600 2018-10-04
Debian Linux HIGH 7.5
CVE-2018-14648EPSS 6%

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An un…

Fix: 1.4.0.17+
Fix from $1,950 2018-09-28
Debian Linux MEDIUM 6.5
CVE-2018-17581

CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of se…

Patch available
Fix from $1,600 2018-09-28
E Alert Firmware HIGH 7.5
CVE-2018-8854

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or amount of resources requested …

No fix yet
Fix from $1,950 2018-09-26
Debian Linux HIGH 7.5
CVE-2018-17281EPSS 53%

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 1…

Fix: after 15.6.0
Fix from $1,950 2018-09-24
Rslinx HIGH 7.5
CVE-2018-14827

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethern…

Fix: after 4.00.01
Fix from $1,950 2018-09-20
Tivoli Monitoring HIGH 7.5
CVE-2017-1794

IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of se…

Fix: after 6.3.0.7
Fix from $1,950 2018-09-19
Enterprise Linux Aus HIGH 7.5
CVE-2018-14638

A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connec…

Fix: 1.3.8.4+
Fix from $1,950 2018-09-14
Debian Linux HIGH 7.5
CVE-2018-16949

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded…

Fix: 1.6.23 / 1.8.2+
Fix from $1,950 2018-09-12
389 Directory Server MEDIUM 6.5
CVE-2018-10935

A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

Fix: 1.3.8.7 / 1.4.0.14+
Fix from $1,600 2018-09-11
Undertow MEDIUM 6.5
CVE-2018-1114

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors…

Mitigation only
Fix from $1,600 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7068EPSS 7%

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacke…

Fix: 3.4.11 / 3.7.4+
Fix from $1,950 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7072EPSS 6%

An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of ser…

Fix: 3.4.11 / 4.0.2+
Fix from $1,950 2018-09-10
Smartos MEDIUM 5.5
CVE-2016-9040

An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl…

No fix yet
Fix from $1,600 2018-09-07
Tg588v Firmware MEDIUM 6.5
CVE-2018-16310

Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonst…

No fix yet
Fix from $1,600 2018-09-06