Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2021-22965 A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed r… Connect Secure 9.1+ Fix from $1,9502021-11-19 MEDIUM 5.5 CVE-2021-33073 Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to pote… Distribution Of Openvino Toolkit 2021.4+ Fix from $1,6002021-11-17 HIGH 8.4 CVE-2021-0180 Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privileg… Hardware Accelerated Execution Manager 7.6.6+ Fix from $1,9502021-11-17 MEDIUM 6.2 CVE-2021-0182 Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable informat… Hardware Accelerated Execution Manager 7.6.6+ Fix from $1,6002021-11-17 MEDIUM 6.5 CVE-2021-41229 BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will … Debian Linux No fix yet Fix from $1,6002021-11-12 MEDIUM 6.5 CVE-2021-3912 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat… Debian Linux 1.3.0+ Fix from $1,6002021-11-11 HIGH 7.5 CVE-2021-3908 OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne… Debian Linux 1.3.0+ Fix from $1,9502021-11-11 HIGH 7.5 CVE-2021-3909 OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically… Debian Linux 1.3.0+ Fix from $1,9502021-11-11 HIGH 7.5 CVE-2002-20001EPSS 23% The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys,… Big Ip Access Policy Manager 16.1.4 / 17.1.0+ Fix from $1,9502021-11-11 HIGH 7.5 CVE-2021-43173 In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feedin… Debian Linux 0.10.2+ Fix from $1,9502021-11-09 HIGH 7.5 CVE-2021-36187 A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial o… Fortiweb after 6.3.15 Fix from $1,9502021-11-02 MEDIUM 5.5 CVE-2020-21573 An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file. Image Processing Mitigation only Fix from $1,6002021-11-02 MEDIUM 6.5 CVE-2021-32595 Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to… Fortiportal 5.3.7 / 6.0.6+ Fix from $1,6002021-11-02 HIGH 7.5 CVE-2021-41186 Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd… Fluentd after 1.14.1 Fix from $1,9502021-10-29 MEDIUM 6.5 CVE-2020-10005 A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. An attacker in a privileged ne… macOS 11.0.1+ Fix from $1,6002021-10-28 HIGH 7.5 CVE-2021-34792 A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow … Secure Firewall Threat Defense 6.4.0.13 / 6.6.5+ Fix from $1,9502021-10-27 HIGH 7.5 CVE-2021-40117 A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software cou… Adaptive Security Appliance 6.2.3.17 / 6.4.0.13+ Fix from $1,9502021-10-27 MEDIUM 6.5 CVE-2021-40125 A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower… Secure Firewall Threat Defense 6.4.0.13 / 6.6.5+ Fix from $1,6002021-10-27 HIGH 7.5 CVE-2021-22101 Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers … Capi Release 1.118.0 / 16.24.0+ Fix from $1,9502021-10-27 HIGH 7.5 CVE-2021-41145 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.10.7+ Fix from $1,9502021-10-25 HIGH 7.5 CVE-2021-42836 GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack. Gjson 1.9.3+ Fix from $1,9502021-10-22 HIGH 8.1 CVE-2021-38463 The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functio… Versiondog 8.0.0+ Fix from $1,9502021-10-22 MEDIUM 6.5 CVE-2021-38465 The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by gene… Versiondog 8.0.0+ Fix from $1,6002021-10-22 MEDIUM 6.5 CVE-2021-41168 Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was foun… Snudown 1.7.0+ Fix from $1,6002021-10-21 HIGH 7.5 CVE-2021-41167 modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affe… Modern Async 1.0.4+ Fix from $1,9502021-10-20 MEDIUM 5.3 CVE-2021-35559EPSS 16% Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected ar… Openjdk after 11.50.2 Fix from $1,6002021-10-20 MEDIUM 6.5 CVE-2021-31365 An Uncontrolled Resource Consumption vulnerability in Juniper Networks Junos OS on EX2300, EX3400 and EX4300 Series platforms allows an adjacent atta… Junos 18.1+ Fix from $1,6002021-10-19 HIGH 7.5 CVE-2021-31368 An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cau… Junos 18.1+ Fix from $1,9502021-10-19 HIGH 7.5 CVE-2021-37136EPSS 6% The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size u… Debian Linux 2.2.4 / 4.1.68+ Fix from $1,9502021-10-19 HIGH 7.5 CVE-2021-37137EPSS 7% The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved… Debian Linux 4.1.68 / 12.0.0.4.6+ Fix from $1,9502021-10-19