Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2019-0059 A memory leak vulnerability in the of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending specif… Junos Mitigation only Fix from $1,9502019-10-09 HIGH 7.5 CVE-2019-15226EPSS 65% Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays… Envoy Patch available Fix from $1,9502019-10-09 HIGH 7.5 CVE-2019-6015 FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue where they may behave as open … Fon2601e Se Firmware after 1.1.7 Fix from $1,9502019-10-04 HIGH 8.6 CVE-2019-15256 A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat… Adaptive Security Appliance Software 6.2.3.11 / 6.3.0.2+ Fix from $1,9502019-10-02 MEDIUM 6.5 CVE-2019-12714 A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cau… Ic3000 Industrial Compute Gateway Firmware 1.1.1+ Fix from $1,6002019-10-02 HIGH 7.5 CVE-2019-12698 A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could all… Adaptive Security Appliance 6.2.3.15 / 6.3.0.5+ Fix from $1,9502019-10-02 MEDIUM 6.5 CVE-2019-12700 A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepo… Firepower 9300 Firmware 2.3.1.155 / 2.6.1.131+ Fix from $1,6002019-10-02 MEDIUM 6.5 CVE-2019-9349 In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi… Android Mitigation only Fix from $1,6002019-09-27 HIGH 7.5 CVE-2019-12659 A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. T… Ios Xe Mitigation only Fix from $1,9502019-09-25 HIGH 7.5 CVE-2019-12658 A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesy… Ios Xe Mitigation only Fix from $1,9502019-09-25 MEDIUM 6.5 CVE-2019-9717 In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_t… Libav after 12.3 Fix from $1,6002019-09-19 HIGH 7.5 CVE-2019-4183 IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send specially crafted requests tha… Cognos Analytics Patch available Fix from $1,9502019-09-17 HIGH 7.5 CVE-2019-1967 A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial … Nx Os Mitigation only Fix from $1,9502019-08-30 HIGH 7.5 CVE-2019-11060 The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause … Hg100 Firmware after 1.05.12 Fix from $1,9502019-08-29 HIGH 7.7 CVE-2019-1965 A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH p… Nx Os 6.2 / 7.0+ Fix from $1,9502019-08-28 HIGH 7.5 CVE-2019-15549 An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplying a large value in a length f… Asn1 Der 0.6.2+ Fix from $1,9502019-08-26 HIGH 7.5 CVE-2019-15538 An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on acc… Linux Kernel 4.9.191 / 4.14.141+ Fix from $1,9502019-08-25 CRITICAL 9.8 CVE-2019-10747 set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying proper… Set Value 2.0.1 / 3.0.1+ Fix from $2,3002019-08-23 CRITICAL 9.8 CVE-2019-10750 deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties o… Deeply 3.1.0+ Fix from $2,3002019-08-23 MEDIUM 5.5 CVE-2019-4049 IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill up the disk space of the unde… Mq after 9.1.1 Fix from $1,6002019-08-20 HIGH 8.2 CVE-2019-9583 eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected ve… Homematic Ccu3 Firmware No fix yet Fix from $1,9502019-08-14 HIGH 7.5 CVE-2019-9518EPSS 25% Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9511EPSS 60% Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9512EPSS 83% Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/… Traffic Server 8.16.1 / 10.16.3+ Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9513EPSS 82% Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request strea… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9514EPSS 83% Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9515EPSS 87% Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 MEDIUM 6.5 CVE-2019-9516EPSS 56% Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with … Traffic Server after 8.0.3 Fix from $1,6002019-08-13 HIGH 7.5 CVE-2019-9517EPSS 28% Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th… HTTP Server 2.4.40+ Fix from $1,9502019-08-13 HIGH 8.6 CVE-2019-10942 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch fam… Scalance X 200 Firmware Mitigation only Fix from $1,9502019-08-13