Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Linux Kernel HIGH 7.5
CVE-2018-5391EPSS 32%

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-as…

Fix: after 4.18
Fix from $1,950 2018-09-06
Linux Kernel MEDIUM 5.5
CVE-2018-6554

Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows lo…

Fix: 4.17+
Fix from $1,600 2018-09-04
FreeBSD HIGH 7.5
CVE-2018-6923

In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive s…

Mitigation only
Fix from $1,950 2018-09-04
Glusterfs MEDIUM 6.5
CVE-2018-10924

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial o…

Fix: 3.12.14 / 4.1.4+
Fix from $1,600 2018-09-04
Bsafe MEDIUM 6.5
CVE-2018-11056

RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Unco…

Fix: 4.0.5.3 / 4.1.6.1+
Fix from $1,600 2018-08-31
Akka Http HIGH 7.5
CVE-2018-16131

The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to …

Fix: after 10.1.4
Fix from $1,950 2018-08-30
Signal HIGH 8.6
CVE-2018-16132

The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large imag…

Fix: after 2.29.0
Fix from $1,950 2018-08-29
Tc8305c Firmware MEDIUM 6.5
CVE-2018-15907

Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresse…

No fix yet
Fix from $1,600 2018-08-29
Traffic Server MEDIUM 5.3
CVE-2018-8005EPSS 7%

When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance pro…

Fix: after 7.1.3
Fix from $1,600 2018-08-29
Tc7200.20 Firmware MEDIUM 6.5
CVE-2018-15852

Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonst…

No fix yet
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15853

Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon user…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Routeros MEDIUM 6.5
CVE-2018-1157

Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability. An authenticated remote attacker can crash the HTTP se…

Fix: 6.40.9 / 6.42.7+
Fix from $1,600 2018-08-23
Hdf5 MEDIUM 6.5
CVE-2018-15671

An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c durin…

No fix yet
Fix from $1,600 2018-08-21
Imagemagick MEDIUM 6.5
CVE-2018-15607EPSS 5%

In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result i…

No fix yet
Fix from $1,600 2018-08-21
Encryption Management Server HIGH 7.5
CVE-2018-5243

The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS …

Fix: after 3.4.2
Fix from $1,950 2018-08-20
Debian Linux MEDIUM 6.5
CVE-2018-15469

An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an…

Fix: after 4.11.0
Fix from $1,600 2018-08-17
Xen MEDIUM 6.5
CVE-2018-15470

An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making …

Fix: after 4.11.0
Fix from $1,600 2018-08-17
Jboss Core Services MEDIUM 6.5
CVE-2016-9596

libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack con…

Fix: 2.9.4+
Fix from $1,600 2018-08-16
Ios Xr HIGH 8.6
CVE-2018-0418

A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow a…

Fix: after 6.3.3_base
Fix from $1,950 2018-08-15
Web Security Appliance HIGH 8.6
CVE-2018-0410

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote att…

Mitigation only
Fix from $1,950 2018-08-15
Certification MEDIUM 6.2
CVE-2018-10864

An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide …

Mitigation only
Fix from $1,600 2018-08-13
FreeBSD MEDIUM 5.3
CVE-2018-6922

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses a…

Patch available
Fix from $1,600 2018-08-09
Virtualization HIGH 7.5
CVE-2018-5390EPSS 74%

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet…

Fix: 4.18+
Fix from $1,950 2018-08-06
Phpcms HIGH 7.5
CVE-2018-14940

PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?…

No fix yet
Fix from $1,950 2018-08-05
Glance MEDIUM 6.5
CVE-2016-8611

A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method fo…

Mitigation only
Fix from $1,600 2018-07-31
Puma Firmware HIGH 7.5
CVE-2017-5693

Firmware in the Intel Puma 5, 6, and 7 Series might experience resource depletion or timeout, which allows a network attacker to create a denial of s…

Mitigation only
Fix from $1,950 2018-07-31
Telem Gwm Firmware HIGH 7.5
CVE-2018-10607

Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, wit…

Fix: after 2018.04.18-linux_4-01-601cb47
Fix from $1,950 2018-07-31
Virtualization HIGH 8.6
CVE-2017-15119

The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sen…

Fix: 2.11.0+
Fix from $1,950 2018-07-27
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5530

F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb".

Fix: after 13.1.0.5
Fix from $1,950 2018-07-25
Big Ip Application Security Manager HIGH 7.5
CVE-2018-5541

When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an unusually large number of para…

Fix: after 13.1.0
Fix from $1,950 2018-07-25