Vulnerability index

Browse CVEs

1,784 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory LeakCWE-401 × clear
Imagemagick MEDIUM 5.5
CVE-2020-27753

There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be triggered by a specially crafted …

Fix: 6.9.10-69 / 7.0.9-0+
Fix from $1,600 2020-12-08
Wildfly MEDIUM 5.9
CVE-2020-27822

A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the…

Mitigation only
Fix from $1,600 2020-12-08
Linux Kernel MEDIUM 5.5
CVE-2020-25704

A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could u…

Fix: after 5.9
Fix from $1,600 2020-12-02
Edk2 HIGH 7.5
CVE-2019-14559

Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.

Mitigation only
Fix from $1,950 2020-11-23
Pparam HIGH 7.5
CVE-2020-28723

Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.

No fix yet
Fix from $1,950 2020-11-16
Wildfly MEDIUM 6.5
CVE-2020-25689

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connec…

Fix: after 21.0.0
Fix from $1,600 2020-11-02
Adaptive Security Appliance HIGH 8.6
CVE-2020-3572

A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software …

Fix: 6.3.0.6 / 6.4.0.10+
Fix from $1,950 2020-10-21
Secure Firewall Threat Defense HIGH 8.6
CVE-2020-3373

A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FT…

Mitigation only
Fix from $1,950 2020-10-21
Esxi MEDIUM 5.3
CVE-2020-3995

In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the…

Fix: 3.9 / 11.1.0+
Fix from $1,600 2020-10-20
Junos HIGH 7.5
CVE-2020-1683

On Juniper Networks Junos OS devices, a specific SNMP OID poll causes a memory leak which over time leads to a kernel crash (vmcore). Prior to the ke…

Mitigation only
Fix from $1,950 2020-10-16
Junos MEDIUM 6.5
CVE-2020-1678

On Juniper Networks Junos OS and Junos OS Evolved platforms with EVPN configured, receipt of specific BGP packets causes a slow memory leak. If the m…

Mitigation only
Fix from $1,600 2020-10-16
Crossbeam CRITICAL 9.8
CVE-2020-15254

Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec:…

Fix: 0.4.4+
Fix from $2,300 2020-10-16
Firecracker HIGH 7.5
CVE-2020-27174

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sen…

Fix: 0.21.3 / 0.22.1+
Fix from $1,950 2020-10-16
Automation Runtime HIGH 7.5
CVE-2020-11637

A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthen…

Fix: after 4.10
Fix from $1,950 2020-10-15
8000p Ip Camera Firmware MEDIUM 6.5
CVE-2020-3543

A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker …

Mitigation only
Fix from $1,600 2020-10-08
Wildfly Openssl HIGH 7.5
CVE-2020-25644

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to caus…

Fix: 1.1.3+
Fix from $1,950 2020-10-06
Sized Chunks HIGH 7.5
CVE-2020-25794

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, clone can have a memory-safety issue upon a pa…

Fix: after 0.6.2
Fix from $1,950 2020-09-19
Sized Chunks HIGH 7.5
CVE-2020-25795

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, insert_from can have a memory-safety issue upo…

Fix: after 0.6.2
Fix from $1,950 2020-09-19
8000p Ip Camera Firmware MEDIUM 6.5
CVE-2020-3505

A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker …

Mitigation only
Fix from $1,600 2020-08-26
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2020-5924

In BIG-IP APM versions 12.1.0-12.1.5.1 and 11.6.1-11.6.5.2, RADIUS authentication leaks memory when the username for authentication is not set.

Fix: 12.1.5.2+
Fix from $1,600 2020-08-26
Acrobat Dc MEDIUM 5.5
CVE-2020-9697

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a discl…

Fix: after 20.009.20074
Fix from $1,600 2020-08-19
Desktop MEDIUM 5.5
CVE-2020-8229

A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.

Fix: 2.6.5+
Fix from $1,600 2020-08-10
Whoopsie MEDIUM 5.5
CVE-2020-11937

In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource ex…

No fix yet
Fix from $1,600 2020-08-06
P30 Firmware MEDIUM 6.5
CVE-2020-9249

HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A module does not deal with mal-cr…

Fix: 10.1.0.160+
Fix from $1,600 2020-07-31
Mq Appliance HIGH 7.5
CVE-2020-4375

IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak c…

Fix: 8.0.0.15 / 9.1.0.6+
Fix from $1,950 2020-07-28
Control For Beaglebone HIGH 7.5
CVE-2020-15806

CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.

Fix: 3.5.16.10+
Fix from $1,950 2020-07-22
Junos MEDIUM 6.5
CVE-2020-1651

On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the packet forwarding engine (PFE)…

Mitigation only
Fix from $1,600 2020-07-17
Tomcat HIGH 7.5
CVE-2020-13934EPSS 64%

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after…

Fix: after 9.0.36
Fix from $1,950 2020-07-14
Wpantund MEDIUM 5.5
CVE-2020-8916

A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is d…

Fix: after 2020-05-28
Fix from $1,600 2020-07-07
Envoy HIGH 7.5
CVE-2020-12604

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload …

Fix: after 1.12.4
Fix from $1,950 2020-07-01