Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Debian Linux MEDIUM 6.8
CVE-2024-28102

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service att…

Fix: 1.5.6+
Fix from $1,600 2024-03-21
Firebird HIGH 7.5
CVE-2023-41038

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific fo…

Fix: after 4.0.3
Fix from $1,950 2024-03-20
Linux Kernel HIGH 7.5
CVE-2021-47130

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p …

Fix: 5.10.43 / 5.12.10+
Fix from $1,950 2024-03-15
Mattermost Server MEDIUM 6.5
CVE-2024-28053

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an …

Fix: 8.1.10+
Fix from $1,600 2024-03-15
Netiq Privileged Account Manager HIGH 7.5
CVE-2020-11862

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Floo…

Fix: 3.7.0.2+
Fix from $1,950 2024-03-13
Quiche HIGH 7.5
CVE-2024-1765

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usa…

Fix: 0.19.2+
Fix from $1,950 2024-03-12
Linux Kernel MEDIUM 5.5
CVE-2024-26618

In the Linux kernel, the following vulnerability has been resolved: arm64/sme: Always exit sme_alloc() early with existing storage When sme_alloc()…

Fix: 6.6.15 / 6.7.3+
Fix from $1,600 2024-03-11
Linux Kernel MEDIUM 5.5
CVE-2023-52606

In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sst…

Fix: 4.19.307 / 5.4.269+
Fix from $1,600 2024-03-06
Unclassified MEDIUM 6.5
CVE-2023-45290

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Requ…

Mitigation only
Fix from $1,600 2024-03-05
Cloud Foundation HIGH 7.1
CVE-2024-22255

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrativ…

Fix: 13.5.1 / 17.5.1+
Fix from $1,950 2024-03-05
Linux Kernel MEDIUM 6.0
CVE-2023-52529

In the Linux kernel, the following vulnerability has been resolved: HID: sony: Fix a potential memory leak in sony_probe() If an error occurs after…

Fix: 5.15.135 / 6.1.57+
Fix from $1,600 2024-03-02
Linux Kernel MEDIUM 5.5
CVE-2023-52518

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_codec: Fix leaking content of local_codecs The following memory …

Fix: 6.1.57 / 6.5.7+
Fix from $1,600 2024-03-02
Linux Kernel MEDIUM 5.5
CVE-2021-47057

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to map In the …

Fix: 5.10.37 / 5.11.21+
Fix from $1,600 2024-02-29
Kerberos 5 HIGH 7.5
CVE-2024-26461

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

No fix yet
Fix from $1,950 2024-02-29
Nx Os HIGH 8.6
CVE-2024-20321

A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,950 2024-02-29
Jose2go HIGH 7.5
CVE-2023-50658

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Fix: 1.6.0+
Fix from $1,950 2024-02-29
Couchbase Server MEDIUM 6.5
CVE-2023-45873

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

Fix: 7.2.3+
Fix from $1,600 2024-02-28
Fedora HIGH 7.5
CVE-2024-23835

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excess…

Fix: 7.0.3+
Fix from $1,950 2024-02-26
Fedora HIGH 7.5
CVE-2024-23836

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.…

Fix: 6.0.16 / 7.0.3+
Fix from $1,950 2024-02-26
Fedora HIGH 7.5
CVE-2024-23837

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of se…

Fix: 0.5.46+
Fix from $1,950 2024-02-26
Debian Linux HIGH 7.5
CVE-2024-22201

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.…

Fix: 9.4.54 / 10.0.20+
Fix from $1,950 2024-02-26
Oncommand Insight MEDIUM 6.5
CVE-2022-34357

IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By m…

Fix: 11.1.7 / 11.2.4+
Fix from $1,600 2024-02-26
Emberznet HIGH 7.5
CVE-2023-51393

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v…

Fix: 7.4.0+
Fix from $1,950 2024-02-23
M Files Server MEDIUM 6.5
CVE-2024-0563

Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of serv…

Fix: 23.2.12340.6 / 23.8.12892.6+
Fix from $1,600 2024-02-23
Liferay Portal MEDIUM 6.5
CVE-2024-26265

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before …

Fix: 7.2 / 7.4.3.16+
Fix from $1,600 2024-02-20
Moodle HIGH 7.5
CVE-2024-25978

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

Fix: 4.1.9 / 4.2.6+
Fix from $1,950 2024-02-19
Commons Compress MEDIUM 5.5
CVE-2024-26308

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 b…

Fix: 1.26.0+
Fix from $1,600 2024-02-19
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-23979

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, …

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2024-21771

For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in T…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Enterprise Linux HIGH 7.5
CVE-2023-50387EPSS 100%

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU…

Patch available
Fix from $1,950 2024-02-14