Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 5.5 CVE-2023-25179 Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentially enabl… Unite after 17 Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2022-46645 Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potentially … Smart Campus 9.9+ Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2022-41801 Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially en… Connect M 1.82+ Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2022-4008 In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service Octopus Server 2022.3.11043 / 2022.4.8401+ Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2023-22874 IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216. Mq Appliance 9.3.0.5 / 9.3.2+ Fix from $1,6002023-05-05 MEDIUM 5.3 CVE-2023-24594 When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   N… Big Ip Access Policy Manager Mitigation only Fix from $1,6002023-05-03 HIGH 7.5 CVE-2023-28882 Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a seg… Modsecurity 3.0.9+ Fix from $1,9502023-04-28 MEDIUM 5.5 CVE-2023-30406 Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c. Jerryscript No fix yet Fix from $1,6002023-04-24 MEDIUM 5.5 CVE-2023-30408 Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry. Jerryscript No fix yet Fix from $1,6002023-04-24 MEDIUM 5.3 CVE-2023-29479 Ribose RNP before 0.16.3 may hang when the input is malformed. Rnp 0.16.3+ Fix from $1,6002023-04-24 HIGH 7.5 CVE-2023-30798 There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify an… Starlette 0.25.0+ Fix from $1,9502023-04-21 MEDIUM 5.5 CVE-2023-27652 An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field… Super Clean No fix yet Fix from $1,6002023-04-20 HIGH 7.5 CVE-2022-24035 An issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g., link fai… Onos No fix yet Fix from $1,9502023-04-20 MEDIUM 6.5 CVE-2022-24109 An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent with a differ… Onos No fix yet Fix from $1,6002023-04-20 HIGH 7.5 CVE-2023-0383 User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. M Files Server 23.4.12528.1+ Fix from $1,9502023-04-20 HIGH 7.5 CVE-2023-0384 User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a … M Files Server 23.4.12528.1+ Fix from $1,9502023-04-20 MEDIUM 5.0 CVE-2023-21090 In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of serv… Android Patch available Fix from $1,6002023-04-19 MEDIUM 5.3 CVE-2023-26048 Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) th… Jetty 9.4.51 / 10.0.14+ Fix from $1,6002023-04-18 HIGH 7.5 CVE-2023-21996 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are … Weblogic Server Mitigation only Fix from $1,9502023-04-18 HIGH 7.5 CVE-2023-21964 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3… Weblogic Server Mitigation only Fix from $1,9502023-04-18 MEDIUM 5.3 CVE-2023-21925 Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are aff… Health Sciences Inform 6.3.1.3+ Fix from $1,6002023-04-18 CRITICAL 9.8 CVE-2023-30769 Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, send it to individual nodes and… Dogecoin 1.14.6+ Fix from $2,3002023-04-17 HIGH 7.5 CVE-2022-40946EPSS 8% On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a c… Dir 819 Firmware No fix yet Fix from $1,9502023-04-16 HIGH 7.5 CVE-2021-39295 In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface. Openbmc No fix yet Fix from $1,9502023-04-15 HIGH 7.5 CVE-2023-29013 Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsin… Traefik 2.9.10+ Fix from $1,9502023-04-14 HIGH 7.5 CVE-2023-27643 An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue … Poweramp No fix yet Fix from $1,9502023-04-14 HIGH 7.5 CVE-2023-30635 TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from the Placement Driver. Tikv No fix yet Fix from $1,9502023-04-13 MEDIUM 6.5 CVE-2023-20863 In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression … Spring Framework 5.2.24 / 5.3.27+ Fix from $1,6002023-04-13 MEDIUM 6.5 CVE-2023-1994 GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file Wireshark 3.6.13 / 4.0.5+ Fix from $1,6002023-04-12 HIGH 7.5 CVE-2023-24545 On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by se… Cloudeos 4.26.9m / 4.27.8m+ Fix from $1,9502023-04-12