Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Lastpass HIGH 7.5
CVE-2018-10193

LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consump…

Fix: after 4.15.0
Fix from $1,950 2018-04-18
Router Firmware HIGH 7.5
CVE-2018-10070EPSS 13%

A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sendi…

No fix yet
Fix from $1,950 2018-04-16
Junos HIGH 7.5
CVE-2018-0022

A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS pa…

Mitigation only
Fix from $1,950 2018-04-11
Micrologix 1400 B Firmware HIGH 7.5
CVE-2017-12090

An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 a…

Fix: after 21.2
Fix from $1,950 2018-04-05
Micrologix 1400 B Firmware MEDIUM 5.3
CVE-2017-12093EPSS 6%

An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B F…

Fix: after 21.2
Fix from $1,600 2018-04-05
Ruby HIGH 7.5
CVE-2018-8777

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with…

Fix: 2.2.10 / 2.3.7+
Fix from $1,950 2018-04-03
Iphone Os HIGH 7.5
CVE-2018-4100

An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected.…

Fix: 4.2.2 / 10.13.3+
Fix from $1,950 2018-04-03
Debian Linux HIGH 7.5
CVE-2018-1064

libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor …

Fix: after 4.1.0
Fix from $1,950 2018-03-28
Truecrypt HIGH 7.1
CVE-2014-2885

Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLeng…

Mitigation only
Fix from $1,950 2018-03-19
Jboss Wildfly Application Server HIGH 7.5
CVE-2016-9589

Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cac…

Fix: after 10.1.0
Fix from $1,950 2018-03-12
Dp300 Firmware MEDIUM 5.5
CVE-2017-15323

Huawei DP300 V500R002C00, NIP6600 V500R001C00, V500R001C20, V500R001C30, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, TE60 V100R001C01, V…

Mitigation only
Fix from $1,600 2018-03-09
Debian Linux MEDIUM 6.5
CVE-2018-7876

In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers t…

No fix yet
Fix from $1,600 2018-03-08
Artemis HIGH 7.5
CVE-2017-12174EPSS 6%

It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when rec…

Fix: 2.4.0+
Fix from $1,950 2018-03-07
Ubuntu Linux HIGH 7.5
CVE-2018-1000115EPSS 88%

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support …

Patch available
Fix from $1,950 2018-03-05
Moment HIGH 7.5
CVE-2017-18214

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability t…

Fix: after 8.2.3
Fix from $1,950 2018-03-04
Ssri MEDIUM 5.9
CVE-2018-7651

index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality vi…

Fix: 5.2.2+
Fix from $1,600 2018-03-04
Debian Linux MEDIUM 5.9
CVE-2017-15130

A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration…

Fix: 2.2.34+
Fix from $1,600 2018-03-02
Streaming Engine HIGH 7.5
CVE-2018-7048

An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request.

Fix: 4.7.1+
Fix from $1,950 2018-03-01
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2018-5500

On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount o…

Fix: after 12.1.3.1
Fix from $1,600 2018-03-01
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2018-5501

In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excess…

Fix: after 12.1.3
Fix from $1,600 2018-03-01
Icinga HIGH 7.5
CVE-2018-6532

An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhau…

Fix: after 2.8.0
Fix from $1,950 2018-02-27
Debian Linux MEDIUM 6.5
CVE-2018-7540

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L…

Fix: after 4.10.0
Fix from $1,600 2018-02-27
PHP MEDIUM 6.5
CVE-2015-9253

An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process i…

Fix: 7.1.20 / 7.2.8+
Fix from $1,600 2018-02-19
Te60 Firmware HIGH 7.5
CVE-2017-17290

The Light Directory Access Protocol (LDAP) clients of Huawei TE60 with software V600R006C00, ViewPoint 9030 with software V100R011C02, V100R011C03 ha…

Mitigation only
Fix from $1,950 2018-02-15
Dp300 Firmware MEDIUM 5.3
CVE-2017-17166

Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V500R001C00, V500R001C20, V500R001C…

Mitigation only
Fix from $1,600 2018-02-15
Lon L29d Firmware MEDIUM 5.3
CVE-2017-15345

Huawei Smartphones with software LON-L29DC721B186 have a denial of service vulnerability. An attacker could make an loop exit condition that cannot b…

Mitigation only
Fix from $1,600 2018-02-15
Android MEDIUM 6.5
CVE-2017-13233

In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service wi…

Mitigation only
Fix from $1,600 2018-02-12
WordPress HIGH 7.5
CVE-2018-6389EPSS 73%

In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js …

Fix: after 4.9.2
Fix from $1,950 2018-02-06
Sandstorm MEDIUM 6.5
CVE-2017-6198

The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by la…

Fix: 0.203+
Fix from $1,600 2018-02-06
Bson CRITICAL 9.8
CVE-2015-4412

BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of servic…

Patch available
Fix from $2,300 2018-02-05