Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2018-14596 wancms 1.0 through 5.0 allows remote attackers to cause a denial of service (resource consumption) via a checkcode (aka verification code) URI in whi… Wancms after 5.0 Fix from $1,9502018-07-25 HIGH 7.5 CVE-2018-10632 In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, … Nport 5230 Firmware Mitigation only Fix from $1,9502018-07-24 HIGH 7.5 CVE-2018-10608EPSS 8% SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, w… Acselerator Architect after 2.2.24.0 Fix from $1,9502018-07-24 HIGH 7.5 CVE-2018-0372 A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an … Nx Os Mitigation only Fix from $1,9502018-07-18 MEDIUM 6.5 CVE-2018-0029 While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system … Junos Mitigation only Fix from $1,6002018-07-11 HIGH 7.5 CVE-2018-0030 Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart. By continuously sending spe… Junos Mitigation only Fix from $1,9502018-07-11 MEDIUM 5.9 CVE-2018-0031 Receipt of specially crafted UDP/IP packets over MPLS may be able to bypass a stateless firewall filter. The crafted UDP packets must be encapsulated… Junos Mitigation only Fix from $1,6002018-07-11 HIGH 7.5 CVE-2016-10724 Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if a… Bitcoin Core 0.13.0+ Fix from $1,9502018-07-05 CRITICAL 9.1 CVE-2018-3767 `memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage. Memjs after 1.1.0 Fix from $2,3002018-07-05 MEDIUM 6.5 CVE-2018-13251 In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, related to parseSWF_DEFINEBITSJP… Libming No fix yet Fix from $1,6002018-07-05 HIGH 7.5 CVE-2018-1000518 aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clie… Websockets Patch available Fix from $1,9502018-06-26 MEDIUM 5.5 CVE-2018-12641 An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling… Binutils No fix yet Fix from $1,6002018-06-22 HIGH 7.7 CVE-2018-0309 A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in … Nx Os Mitigation only Fix from $1,9502018-06-21 HIGH 7.5 CVE-2018-1333EPSS 17% By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of serv… HTTP Server after 2.4.30 Fix from $1,9502018-06-18 MEDIUM 5.5 CVE-2018-12066 BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressio… Bird 1.6.4+ Fix from $1,6002018-06-08 HIGH 7.5 CVE-2017-6779 Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that co… Emergency Responder 10.5 / 10.5.2+ Fix from $1,9502018-06-07 CRITICAL 9.1 CVE-2018-3739 https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory le… Https Proxy Agent 2.2.0+ Fix from $2,3002018-06-07 MEDIUM 5.9 CVE-2017-16129 The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that be… Superagent 3.7.0+ Fix from $1,6002018-06-07 HIGH 7.5 CVE-2017-16136 method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't suppo… Method Override 2.3.10+ Fix from $1,9502018-06-07 MEDIUM 5.3 CVE-2017-16137 The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k … Debug 2.6.9 / 3.1.0+ Fix from $1,6002018-06-07 HIGH 7.5 CVE-2017-16138 The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input. Mime 1.4.1 / 2.0.3+ Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16098 charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around … Charset 1.0.1+ Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16099 The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the… No Case 2.3.2+ Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16111 The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulne… Content after 3.0.5 Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16113 The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed. Parsejson after 0.0.3 Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16114 The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can … Marked 0.3.9+ Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16115 The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop … Timespan Mitigation only Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16116 The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when spe… String after 3.3.3 Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16117 slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted un… Slug after 0.9.1 Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16118 The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of ser… Forwarded 0.1.2+ Fix from $1,9502018-06-07