Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 5.5 CVE-2012-0879 The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to… Linux Kernel 2.6.33+ Fix from $1,6002012-05-17 HIGH 7.5 CVE-2012-0382 The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.… iOS 3.2.2sg / 3.4.1s+ Fix from $1,9502012-03-29 MEDIUM 5.0 CVE-2011-3954 Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of … Chrome 17.0.963.46+ Fix from $1,6002012-02-09 HIGH 7.8 CVE-2012-0024 MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predict… Maradns 1.3.07.12 / 1.4.08+ Fix from $1,9502012-01-08 MEDIUM 5.0 CVE-2011-4838 JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent atta… Jruby 1.6.5.1+ Fix from $1,6002011-12-30 HIGH 7.5 CVE-2011-1640 The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large number of LLDP Management Address (MA) TLVs, whic… iOS 12.2+ Fix from $1,9502011-10-22 HIGH 7.5 CVE-2011-2189EPSS 18% net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, w… Linux Kernel after 2.6.32 Fix from $1,9502011-10-10 HIGH 7.8 CVE-2011-3192EPSS 99% The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of ser… HTTP Server 2.0.65 / 2.2.20+ Fix from $1,9502011-08-29 HIGH 7.5 CVE-2010-4251 The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows r… Linux Kernel 2.6.34+ Fix from $1,9502011-05-26 HIGH 7.5 CVE-2010-4805 The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows r… Linux Kernel 2.6.35+ Fix from $1,9502011-05-26 HIGH 7.5 CVE-2011-0985 Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack … Chrome 9.0.597.94+ Fix from $1,9502011-02-10 HIGH 7.8 CVE-2010-4686 CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" reques… iOS 15.0+ Fix from $1,9502011-01-07 HIGH 7.8 CVE-2010-4671 The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of ser… iOS 15.0+ Fix from $1,9502011-01-07 HIGH 8.3 CVE-2010-3705 The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP pe… Linux Kernel 2.6.36+ Fix from $1,9502010-11-26 MEDIUM 5.5 CVE-2009-3621 net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-nam… Linux Kernel after 2.6.31.4 Fix from $1,6002009-10-22 MEDIUM 5.0 CVE-2009-2521EPSS 82% Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users… Internet Information Services after 7.0 Fix from $1,6002009-09-04 HIGH 7.5 CVE-2009-2541 The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a larg… Playstation 3 No fix yet Fix from $1,9502009-07-20 HIGH 7.1 CVE-2009-1891EPSS 17% The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is clo… HTTP Server 2.0.64 / 2.2.12+ Fix from $1,9502009-07-10 HIGH 7.1 CVE-2009-1890EPSS 16% The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured… HTTP Server 2.2.12+ Fix from $1,9502009-07-05 HIGH 7.8 CVE-2008-4077 The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (reso… Ledgersmb 1.2.15+ Fix from $1,9502008-09-15 MEDIUM 5.0 CVE-2008-0132EPSS 9% Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the admini… Fortress Ssh 5.0+ Fix from $1,6002008-01-08 HIGH 7.5 CVE-2006-7229 The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attackers to … Linux Kernel Mitigation only Fix from $1,9502007-11-15 MEDIUM 6.8 CVE-2007-4725EPSS 6% Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assis… 7 Zip after 4.42 Fix from $1,6002007-09-05 MEDIUM 5.0 CVE-2007-1377EPSS 17% AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspec… Firefox No fix yet Fix from $1,6002007-03-10 HIGH 7.8 CVE-2007-0086EPSS 10% The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (networ… HTTP Server Mitigation only Fix from $1,9502007-01-05 MEDIUM 5.5 CVE-2006-5648 Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list a… Ubuntu Linux Patch available Fix from $1,6002006-12-14 MEDIUM 5.5 CVE-2006-5649 Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to … Ubuntu Linux Patch available Fix from $1,6002006-12-14 MEDIUM 6.5 CVE-2006-6017 WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated… WordPress after 2.0.5 Fix from $1,6002006-11-21 HIGH 7.5 CVE-2006-6025 QUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. NOTE: The… Eudora Worldmail No fix yet Fix from $1,9502006-11-21 HIGH 7.5 CVE-2006-5708 Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of servic… Mdaemon after 9.50 Fix from $1,9502006-11-04