Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Wancms HIGH 7.5
CVE-2018-14596

wancms 1.0 through 5.0 allows remote attackers to cause a denial of service (resource consumption) via a checkcode (aka verification code) URI in whi…

Fix: after 5.0
Fix from $1,950 2018-07-25
Nport 5230 Firmware HIGH 7.5
CVE-2018-10632

In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, …

Mitigation only
Fix from $1,950 2018-07-24
Acselerator Architect HIGH 7.5
CVE-2018-10608EPSS 8%

SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, w…

Fix: after 2.2.24.0
Fix from $1,950 2018-07-24
Nx Os HIGH 7.5
CVE-2018-0372

A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an …

Mitigation only
Fix from $1,950 2018-07-18
Junos MEDIUM 6.5
CVE-2018-0029

While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system …

Mitigation only
Fix from $1,600 2018-07-11
Junos HIGH 7.5
CVE-2018-0030

Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart. By continuously sending spe…

Mitigation only
Fix from $1,950 2018-07-11
Junos MEDIUM 5.9
CVE-2018-0031

Receipt of specially crafted UDP/IP packets over MPLS may be able to bypass a stateless firewall filter. The crafted UDP packets must be encapsulated…

Mitigation only
Fix from $1,600 2018-07-11
Bitcoin Core HIGH 7.5
CVE-2016-10724

Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if a…

Fix: 0.13.0+
Fix from $1,950 2018-07-05
Memjs CRITICAL 9.1
CVE-2018-3767

`memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage.

Fix: after 1.1.0
Fix from $2,300 2018-07-05
Libming MEDIUM 6.5
CVE-2018-13251

In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, related to parseSWF_DEFINEBITSJP…

No fix yet
Fix from $1,600 2018-07-05
Websockets HIGH 7.5
CVE-2018-1000518

aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clie…

Patch available
Fix from $1,950 2018-06-26
Binutils MEDIUM 5.5
CVE-2018-12641

An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling…

No fix yet
Fix from $1,600 2018-06-22
Nx Os HIGH 7.7
CVE-2018-0309

A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in …

Mitigation only
Fix from $1,950 2018-06-21
HTTP Server HIGH 7.5
CVE-2018-1333EPSS 17%

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of serv…

Fix: after 2.4.30
Fix from $1,950 2018-06-18
Bird MEDIUM 5.5
CVE-2018-12066

BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressio…

Fix: 1.6.4+
Fix from $1,600 2018-06-08
Emergency Responder HIGH 7.5
CVE-2017-6779

Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that co…

Fix: 10.5 / 10.5.2+
Fix from $1,950 2018-06-07
Https Proxy Agent CRITICAL 9.1
CVE-2018-3739

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory le…

Fix: 2.2.0+
Fix from $2,300 2018-06-07
Superagent MEDIUM 5.9
CVE-2017-16129

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that be…

Fix: 3.7.0+
Fix from $1,600 2018-06-07
Method Override HIGH 7.5
CVE-2017-16136

method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't suppo…

Fix: 2.3.10+
Fix from $1,950 2018-06-07
Debug MEDIUM 5.3
CVE-2017-16137

The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k …

Fix: 2.6.9 / 3.1.0+
Fix from $1,600 2018-06-07
Mime HIGH 7.5
CVE-2017-16138

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

Fix: 1.4.1 / 2.0.3+
Fix from $1,950 2018-06-07
Charset HIGH 7.5
CVE-2017-16098

charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around …

Fix: 1.0.1+
Fix from $1,950 2018-06-07
No Case HIGH 7.5
CVE-2017-16099

The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the…

Fix: 2.3.2+
Fix from $1,950 2018-06-07
Content HIGH 7.5
CVE-2017-16111

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulne…

Fix: after 3.0.5
Fix from $1,950 2018-06-07
Parsejson HIGH 7.5
CVE-2017-16113

The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.

Fix: after 0.0.3
Fix from $1,950 2018-06-07
Marked HIGH 7.5
CVE-2017-16114

The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can …

Fix: 0.3.9+
Fix from $1,950 2018-06-07
Timespan HIGH 7.5
CVE-2017-16115

The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop …

Mitigation only
Fix from $1,950 2018-06-07
String HIGH 7.5
CVE-2017-16116

The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when spe…

Fix: after 3.3.3
Fix from $1,950 2018-06-07
Slug HIGH 7.5
CVE-2017-16117

slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted un…

Fix: after 0.9.1
Fix from $1,950 2018-06-07
Forwarded HIGH 7.5
CVE-2017-16118

The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of ser…

Fix: 0.1.2+
Fix from $1,950 2018-06-07