Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Linux Kernel MEDIUM 5.5
CVE-2024-26816

In the Linux kernel, the following vulnerability has been resolved: x86, relocs: Ignore relocations in .notes section When building with CONFIG_XEN…

Fix: 4.19.311 / 5.4.273+
Fix from $1,600 2024-04-10
Jt2go MEDIUM 5.5
CVE-2024-26276

A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions <…

Fix: 14.2.0.12 / 14.3.0.9+
Fix from $1,600 2024-04-09
Nemo HIGH 7.5
CVE-2024-0081

NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits o…

Mitigation only
Fix from $1,950 2024-04-05
Mattermost Server MEDIUM 6.5
CVE-2024-28949

Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences…

Fix: 8.1.11 / 9.3.3+
Fix from $1,600 2024-04-05
HTTP Server HIGH 7.5
CVE-2024-27316EPSS 91%

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do…

Fix: 2.4.59+
Fix from $1,950 2024-04-04
Unclassified HIGH 8.6
CVE-2024-30249

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR1-20240330.101522-15` i…

Mitigation only
Fix from $1,950 2024-04-04
Websphere Application Server HIGH 7.5
CVE-2024-27268

IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques…

Fix: 24.0.0.5+
Fix from $1,950 2024-04-04
Debian Linux MEDIUM 5.3
CVE-2024-28182EPSS 85%

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbound…

Fix: 1.61.0+
Fix from $1,600 2024-04-04
Libhtp HIGH 7.5
CVE-2024-28871

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading …

Patch available
Fix from $1,950 2024-04-04
Unclassified HIGH 7.5
CVE-2024-22189

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run out of memory sending a large…

Patch available
Fix from $1,950 2024-04-04
Linux Kernel MEDIUM 5.5
CVE-2024-26798

In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do_set_font() Commit a5a923038…

Fix: 5.15.151 / 6.1.81+
Fix from $1,600 2024-04-04
Suricata HIGH 7.5
CVE-2024-28870

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Su…

Fix: 6.0.17 / 7.0.4+
Fix from $1,950 2024-04-03
Linux Kernel MEDIUM 5.5
CVE-2024-26741

In the Linux kernel, the following vulnerability has been resolved: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().…

Fix: 6.1.80 / 6.6.19+
Fix from $1,600 2024-04-03
Linux Kernel MEDIUM 5.5
CVE-2024-26743

In the Linux kernel, the following vulnerability has been resolved: RDMA/qedr: Fix qedr_create_user_qp error flow Avoid the following warning by ma…

Fix: 5.10.211 / 5.15.150+
Fix from $1,600 2024-04-03
Linux Kernel MEDIUM 5.5
CVE-2024-26707

In the Linux kernel, the following vulnerability has been resolved: net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame() Syzkaller reported…

Fix: 5.10.210 / 5.15.149+
Fix from $1,600 2024-04-03
Linux Kernel MEDIUM 5.5
CVE-2024-26710

In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Limit KASAN thread size increase to 32KB KASAN is seen to increa…

Fix: 6.1.79 / 6.6.18+
Fix from $1,600 2024-04-03
Openharmony MEDIUM 5.5
CVE-2024-29086

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.

Fix: after 3.2.4
Fix from $1,600 2024-04-02
Linux Kernel MEDIUM 5.5
CVE-2024-26675

In the Linux kernel, the following vulnerability has been resolved: ppp_async: limit MRU to 64K syzbot triggered a warning [1] in __alloc_pages(): …

Fix: 4.19.307 / 5.4.269+
Fix from $1,600 2024-04-02
Websphere Application Server HIGH 7.5
CVE-2024-22353

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques…

Fix: after 24.0.0.3
Fix from $1,950 2024-03-31
GitLab MEDIUM 6.5
CVE-2024-2818

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starti…

Fix: 16.8.5 / 16.9.3+
Fix from $1,600 2024-03-28
Couchbase Server HIGH 7.5
CVE-2023-43768

An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memo…

Fix: 7.1.5+
Fix from $1,950 2024-03-27
Unclassified HIGH 7.5
CVE-2024-26577

VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet containing at least 10 digits i…

Mitigation only
Fix from $1,950 2024-03-26
Unclassified MEDIUM 6.5
CVE-2024-22436

A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.

No fix yet
Fix from $1,600 2024-03-26
Linux Kernel MEDIUM 5.5
CVE-2024-26646

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel alloca…

Fix: 6.1.76 / 6.6.15+
Fix from $1,600 2024-03-26
Linux Kernel MEDIUM 5.5
CVE-2023-52622

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid online resizing failures due to oversized flex bg When we online re…

Fix: 4.19.307 / 5.4.269+
Fix from $1,600 2024-03-26
Debian Linux MEDIUM 5.3
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients…

Fix: 4.1.108+
Fix from $1,600 2024-03-25
Linux Kernel MEDIUM 5.5
CVE-2021-47170

In the Linux kernel, the following vulnerability has been resolved: USB: usbfs: Don't WARN about excessively large memory allocations Syzbot found …

Fix: 4.19.193 / 5.4.124+
Fix from $1,600 2024-03-25
Linux Kernel CRITICAL 9.8
CVE-2021-47137

In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory alloc…

Fix: 5.4.124 / 5.10.42+
Fix from $2,300 2024-03-25
Unclassified HIGH 7.5
CVE-2024-30156

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an…

Mitigation only
Fix from $1,950 2024-03-24
Tar MEDIUM 6.5
CVE-2024-28863

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An a…

Fix: 6.2.1+
Fix from $1,600 2024-03-21