Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 5.5 CVE-2018-6616 In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerabili… Debian Linux No fix yet Fix from $1,6002018-02-04 HIGH 7.8 CVE-2017-14177 Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker… Ubuntu Linux after 2.20.7 Fix from $1,9502018-02-02 HIGH 7.8 CVE-2017-14179 Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an at… Ubuntu Linux 2.13+ Fix from $1,9502018-02-02 HIGH 7.8 CVE-2017-14180 Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root whi… Ubuntu Linux after 2.20.7 Fix from $1,9502018-02-02 HIGH 7.5 CVE-2017-15133 A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from ac… Miekg Dns 1.0.4+ Fix from $1,9502018-01-29 MEDIUM 5.5 CVE-2018-6352 In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverag… Podofo Mitigation only Fix from $1,6002018-01-27 HIGH 7.5 CVE-2017-3768 An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo Syste… Flex System X240 M5 Firmware 4.4+ Fix from $1,9502018-01-26 HIGH 7.5 CVE-2017-15132 A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by log… Debian Linux after 2.2.33 Fix from $1,9502018-01-25 HIGH 7.5 CVE-2018-5748 qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply. Libvirt Patch available Fix from $1,9502018-01-25 HIGH 7.5 CVE-2018-5954EPSS 9% phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. Phpfreechat after 1.7 Fix from $1,9502018-01-25 HIGH 7.5 CVE-2018-4837 A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver (port 80/… Telecontrol Server Basic 3.1+ Fix from $1,9502018-01-25 MEDIUM 6.5 CVE-2018-5784 In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this v… Debian Linux Patch available Fix from $1,6002018-01-19 HIGH 8.6 CVE-2018-0086 A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a… Unified Customer Voice Portal after 11.5 Fix from $1,9502018-01-18 HIGH 7.5 CVE-2018-0090 A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote… Nx Os Mitigation only Fix from $1,9502018-01-18 HIGH 7.5 CVE-2018-0094 A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of… Unified Computing System Central Software Mitigation only Fix from $1,9502018-01-18 HIGH 7.5 CVE-2017-13211 In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received… Android Mitigation only Fix from $1,9502018-01-12 MEDIUM 6.5 CVE-2018-0004 A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS regi… Junos Mitigation only Fix from $1,6002018-01-10 MEDIUM 6.5 CVE-2017-1000476 ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a den… Debian Linux Patch available Fix from $1,6002018-01-03 HIGH 7.5 CVE-2017-17901 ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1. P 660hw Firmware No fix yet Fix from $1,9502017-12-29 HIGH 7.5 CVE-2014-3651 JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter… Keycloak 1.0.3+ Fix from $1,9502017-12-29 HIGH 7.5 CVE-2017-12741 Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually. Simatic S7 200 Firmware 2.0 / 2.03.01+ Fix from $1,9502017-12-26 MEDIUM 6.5 CVE-2017-17682 In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause … Ubuntu Linux No fix yet Fix from $1,6002017-12-14 MEDIUM 6.2 CVE-2017-15529 Prior to 4.4.1.10, the Norton Family Android App can be susceptible to a Denial of Service (DoS) exploit. A DoS attack is a type of attack whereby th… Norton Family 4.4.1.10+ Fix from $1,6002017-12-13 MEDIUM 5.9 CVE-2017-4920 The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the li… Nsx V Edge 6.2.8 / 6.3.3+ Fix from $1,6002017-12-05 HIGH 8.6 CVE-2017-17051 An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticat… Nova Mitigation only Fix from $1,9502017-12-05 HIGH 7.5 CVE-2017-15701 In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remo… Qpid Broker J after 6.1.4 Fix from $1,9502017-12-01 MEDIUM 5.5 CVE-2017-2734 P9 Plus smartphones with software versions earlier before VIE-AL10BC00B386 have a denial of service (DoS) vulnerability. An attacker tricks a user in… P9 Plus Firmware Mitigation only Fix from $1,6002017-11-22 MEDIUM 5.5 CVE-2017-2690 SoftCo with software V200R003C20,eSpace U1910 with software V200R003C00, V200R003C20 and V200R003C30,eSpace U1911 with software V200R003C20, V200R003… Softco Firmware Mitigation only Fix from $1,6002017-11-22 MEDIUM 6.5 CVE-2017-12190 The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector h… Linux Kernel after 4.13.7 Fix from $1,6002017-11-22 HIGH 7.5 CVE-2017-1000191 Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS. Jool Mitigation only Fix from $1,9502017-11-17