Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2023-5330 Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to t… Mattermost Server 7.8.11 / 8.0.3+ Fix from $1,9502023-10-09 MEDIUM 6.5 CVE-2023-5333 Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sendin… Mattermost Server 7.8.11 / 8.0.3+ Fix from $1,6002023-10-09 MEDIUM 5.5 CVE-2023-21253 In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of servi… Android Patch available Fix from $1,6002023-10-06 HIGH 7.5 CVE-2023-43810 OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting, generating, collecting, and e… Opentelemetry 0.41b0+ Fix from $1,9502023-10-06 HIGH 7.5 CVE-2023-20259 A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CP… Emergency Responder Mitigation only Fix from $1,9502023-10-04 MEDIUM 5.3 CVE-2023-3153 A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a de… Openshift Container Platform 22.03.3 / 22.09.2+ Fix from $1,6002023-10-04 HIGH 7.5 CVE-2023-33026 Transient DOS in WLAN Firmware while parsing a NAN management frame. Ar8035 Firmware Mitigation only Fix from $1,9502023-10-03 HIGH 7.5 CVE-2023-26151 Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a re… Opcua Asyncio 0.9.96+ Fix from $1,9502023-10-03 MEDIUM 6.5 CVE-2023-5196 Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_p… Mattermost 7.8.10 / 8.0.2+ Fix from $1,6002023-09-29 HIGH 8.6 CVE-2023-20176 A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary … Catalyst 9166 Firmware 17.6.6+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-5157 A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service. MariaDB 10.3.36 / 10.4.26+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-43646 get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject… Get Func Name 2.0.1+ Fix from $1,9502023-09-27 MEDIUM 5.3 CVE-2023-43775 Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automa… Smp Sg 4260 Firmware 8.0r9 / 8.1r5+ Fix from $1,6002023-09-27 MEDIUM 6.5 CVE-2023-40441 A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Processing we… Ipados 14.0 / 17.0+ Fix from $1,6002023-09-27 CRITICAL 9.8 CVE-2023-41294 The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. Harmonyos No fix yet Fix from $2,3002023-09-25 MEDIUM 5.5 CVE-2023-43771 In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program. Not Quite Ptp 1.2.3+ Fix from $1,6002023-09-22 HIGH 7.5 CVE-2023-43767 Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Ser… Linux Protection Mitigation only Fix from $1,9502023-09-22 HIGH 7.5 CVE-2023-42457 plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3… Rest Patch available Fix from $1,9502023-09-21 MEDIUM 5.3 CVE-2023-26144 Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the Overlapping… Graphql 16.8.1+ Fix from $1,6002023-09-20 MEDIUM 5.5 CVE-2020-24089 An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DoS). Malware Fighter Mitigation only Fix from $1,6002023-09-20 MEDIUM 6.5 CVE-2022-47556 Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send continuous legitimate web req… Ekorrci Firmware Mitigation only Fix from $1,6002023-09-19 HIGH 7.5 CVE-2023-42521 Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15… Client Security Mitigation only Fix from $1,9502023-09-18 HIGH 7.5 CVE-2023-42522 Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client… Client Security Mitigation only Fix from $1,9502023-09-18 HIGH 7.5 CVE-2023-42523 Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSec… Client Security Mitigation only Fix from $1,9502023-09-18 HIGH 7.5 CVE-2023-42520 Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15… Client Security Mitigation only Fix from $1,9502023-09-18 HIGH 7.5 CVE-2023-42526 Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Securit… Client Security Mitigation only Fix from $1,9502023-09-18 HIGH 7.5 CVE-2023-29499 A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service. Glib 2.74.4+ Fix from $1,9502023-09-14 MEDIUM 5.5 CVE-2023-32611 A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading… Glib 2.74.2+ Fix from $1,6002023-09-14 HIGH 7.5 CVE-2023-32636 A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation adde… Glib 2.74.4+ Fix from $1,9502023-09-14 MEDIUM 5.5 CVE-2023-32665 A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processi… Glib 2.74.4+ Fix from $1,6002023-09-14