Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Debian Linux MEDIUM 5.5
CVE-2018-6616

In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerabili…

No fix yet
Fix from $1,600 2018-02-04
Ubuntu Linux HIGH 7.8
CVE-2017-14177

Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker…

Fix: after 2.20.7
Fix from $1,950 2018-02-02
Ubuntu Linux HIGH 7.8
CVE-2017-14179

Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an at…

Fix: 2.13+
Fix from $1,950 2018-02-02
Ubuntu Linux HIGH 7.8
CVE-2017-14180

Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root whi…

Fix: after 2.20.7
Fix from $1,950 2018-02-02
Miekg Dns HIGH 7.5
CVE-2017-15133

A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from ac…

Fix: 1.0.4+
Fix from $1,950 2018-01-29
Podofo MEDIUM 5.5
CVE-2018-6352

In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverag…

Mitigation only
Fix from $1,600 2018-01-27
Flex System X240 M5 Firmware HIGH 7.5
CVE-2017-3768

An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo Syste…

Fix: 4.4+
Fix from $1,950 2018-01-26
Debian Linux HIGH 7.5
CVE-2017-15132

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by log…

Fix: after 2.2.33
Fix from $1,950 2018-01-25
Libvirt HIGH 7.5
CVE-2018-5748

qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.

Patch available
Fix from $1,950 2018-01-25
Phpfreechat HIGH 7.5
CVE-2018-5954EPSS 9%

phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands.

Fix: after 1.7
Fix from $1,950 2018-01-25
Telecontrol Server Basic HIGH 7.5
CVE-2018-4837

A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver (port 80/…

Fix: 3.1+
Fix from $1,950 2018-01-25
Debian Linux MEDIUM 6.5
CVE-2018-5784

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this v…

Patch available
Fix from $1,600 2018-01-19
Unified Customer Voice Portal HIGH 8.6
CVE-2018-0086

A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a…

Fix: after 11.5
Fix from $1,950 2018-01-18
Nx Os HIGH 7.5
CVE-2018-0090

A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote…

Mitigation only
Fix from $1,950 2018-01-18
Unified Computing System Central Software HIGH 7.5
CVE-2018-0094

A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of…

Mitigation only
Fix from $1,950 2018-01-18
Android HIGH 7.5
CVE-2017-13211

In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received…

Mitigation only
Fix from $1,950 2018-01-12
Junos MEDIUM 6.5
CVE-2018-0004

A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS regi…

Mitigation only
Fix from $1,600 2018-01-10
Debian Linux MEDIUM 6.5
CVE-2017-1000476

ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a den…

Patch available
Fix from $1,600 2018-01-03
P 660hw Firmware HIGH 7.5
CVE-2017-17901

ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.

No fix yet
Fix from $1,950 2017-12-29
Keycloak HIGH 7.5
CVE-2014-3651

JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter…

Fix: 1.0.3+
Fix from $1,950 2017-12-29
Simatic S7 200 Firmware HIGH 7.5
CVE-2017-12741

Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.

Fix: 2.0 / 2.03.01+
Fix from $1,950 2017-12-26
Ubuntu Linux MEDIUM 6.5
CVE-2017-17682

In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause …

No fix yet
Fix from $1,600 2017-12-14
Norton Family MEDIUM 6.2
CVE-2017-15529

Prior to 4.4.1.10, the Norton Family Android App can be susceptible to a Denial of Service (DoS) exploit. A DoS attack is a type of attack whereby th…

Fix: 4.4.1.10+
Fix from $1,600 2017-12-13
Nsx V Edge MEDIUM 5.9
CVE-2017-4920

The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the li…

Fix: 6.2.8 / 6.3.3+
Fix from $1,600 2017-12-05
Nova HIGH 8.6
CVE-2017-17051

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticat…

Mitigation only
Fix from $1,950 2017-12-05
Qpid Broker J HIGH 7.5
CVE-2017-15701

In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remo…

Fix: after 6.1.4
Fix from $1,950 2017-12-01
P9 Plus Firmware MEDIUM 5.5
CVE-2017-2734

P9 Plus smartphones with software versions earlier before VIE-AL10BC00B386 have a denial of service (DoS) vulnerability. An attacker tricks a user in…

Mitigation only
Fix from $1,600 2017-11-22
Softco Firmware MEDIUM 5.5
CVE-2017-2690

SoftCo with software V200R003C20,eSpace U1910 with software V200R003C00, V200R003C20 and V200R003C30,eSpace U1911 with software V200R003C20, V200R003…

Mitigation only
Fix from $1,600 2017-11-22
Linux Kernel MEDIUM 6.5
CVE-2017-12190

The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector h…

Fix: after 4.13.7
Fix from $1,600 2017-11-22
Jool HIGH 7.5
CVE-2017-1000191

Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.

Mitigation only
Fix from $1,950 2017-11-17