Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2024-34688 Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, whic… Netweaver Application Server Java Patch available Fix from $1,9502024-06-11 MEDIUM 6.5 CVE-2024-33001 SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of th… Netweaver Application Server Abap Patch available Fix from $1,6002024-06-11 MEDIUM 6.5 CVE-2024-27812 A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service. Visionos 1.2+ Fix from $1,6002024-06-10 MEDIUM 6.5 CVE-2024-27800 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monter… Ipados 1.2 / 10.5+ Fix from $1,6002024-06-10 HIGH 7.5 CVE-2023-51847 An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsaf… Mitigation only Fix from $1,9502024-06-06 MEDIUM 6.5 CVE-2024-3153 mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of serv… Anythingllm 1.0.0+ Fix from $1,6002024-06-06 HIGH 7.5 CVE-2024-36743 An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot. Oneflow Mitigation only Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-33655 The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to … Patch available Fix from $1,9502024-06-06 HIGH 7.8 CVE-2022-28657 Apport does not disable python crash handler before entering chroot Ubuntu Linux 2.21.0+ Fix from $1,9502024-06-04 MEDIUM 6.5 CVE-2024-34364 Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP c… Envoy 1.27.6 / 1.28.4+ Fix from $1,6002024-06-04 HIGH 7.1 CVE-2024-5422 An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertech… Mitigation only Fix from $1,9502024-06-04 HIGH 7.5 CVE-2023-30311 An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of service. Mitigation only Fix from $1,9502024-05-28 MEDIUM 6.5 CVE-2024-22588 Kwik commit 745fd4e2 does not discard unused encryption keys. No fix yet Fix from $1,6002024-05-24 HIGH 7.1 CVE-2021-47371 In the Linux kernel, the following vulnerability has been resolved: nexthop: Fix memory leaks in nexthop notification chain listeners syzkaller dis… Linux Kernel 5.14.9+ Fix from $1,9502024-05-21 HIGH 7.1 CVE-2021-47368 In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() sto… Linux Kernel 5.4.150 / 5.10.70+ Fix from $1,9502024-05-21 MEDIUM 6.2 CVE-2021-47329 In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix resource leak in case of probe failure The driver doesn… Linux Kernel 5.4.134 / 5.10.52+ Fix from $1,6002024-05-21 HIGH 8.4 CVE-2021-47313 In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init It's a classic ex… Linux Kernel 5.12.19 / 5.13.4+ Fix from $1,9502024-05-21 HIGH 7.5 CVE-2021-47295 In the Linux kernel, the following vulnerability has been resolved: net: sched: fix memory leak in tcindex_partial_destroy_work Syzbot reported mem… Linux Kernel 5.4.136 / 5.10.54+ Fix from $1,9502024-05-21 MEDIUM 5.5 CVE-2021-47238 In the Linux kernel, the following vulnerability has been resolved: net: ipv4: fix memory leak in ip_mc_add1_src BUG: memory leak unreferenced obje… Linux Kernel 3.3 / 3.17+ Fix from $1,6002024-05-21 MEDIUM 5.3 CVE-2024-35194 Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaust… Patch available Fix from $1,6002024-05-20 HIGH 7.5 CVE-2024-34953 An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm file No fix yet Fix from $1,9502024-05-20 HIGH 7.8 CVE-2024-35948 In the Linux kernel, the following vulnerability has been resolved: bcachefs: Check for journal entries overruning end of sb clean section Fix a mi… Linux Kernel 6.9+ Fix from $1,9502024-05-20 MEDIUM 5.5 CVE-2024-35799 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent crash when disable stream [Why] Disabling stream encod… Linux Kernel 6.6.26 / 6.7.12+ Fix from $1,6002024-05-17 MEDIUM 5.5 CVE-2023-52672 In the Linux kernel, the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commit c73be61cede5 ("pipe: Add ge… Linux Kernel 5.10.210 / 5.15.149+ Fix from $1,6002024-05-17 HIGH 7.5 CVE-2024-5055 Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to proces… Mitigation only Fix from $1,9502024-05-17 HIGH 7.5 CVE-2024-5052 Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port… Mitigation only Fix from $1,9502024-05-17 HIGH 7.5 CVE-2024-21823 Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow… Mitigation only Fix from $1,9502024-05-16 MEDIUM 5.3 CVE-2024-35176 REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an att… Rexml 3.2.7+ Fix from $1,6002024-05-16 MEDIUM 5.3 CVE-2024-35185 Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack vi… Patch available Fix from $1,6002024-05-16 MEDIUM 6.5 CVE-2023-7258 A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible… Gvisor 20231204.0+ Fix from $1,6002024-05-15