Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Android MEDIUM 5.5
CVE-2022-48440

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

Mitigation only
Fix from $1,600 2023-06-06
Android MEDIUM 5.5
CVE-2022-48441

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

No fix yet
Fix from $1,600 2023-06-06
Thunderbird MEDIUM 6.5
CVE-2023-0616

If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which cou…

Fix: 102.8+
Fix from $1,600 2023-06-02
Firefox MEDIUM 6.5
CVE-2023-23603

Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for externa…

Fix: 102.7 / 109.0+
Fix from $1,600 2023-06-02
Metersphere MEDIUM 6.5
CVE-2023-32699

MeterSphere is an open source continuous testing platform. Version 2.9.1 and prior are vulnerable to denial of service. ​The `checkUserPassword` meth…

Fix: after 2.9.1
Fix from $1,600 2023-05-30
Nanomq MEDIUM 5.5
CVE-2023-33656

A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability…

No fix yet
Fix from $1,600 2023-05-30
Wave Animated Keyboard Emoji MEDIUM 5.5
CVE-2023-29737

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.

No fix yet
Fix from $1,600 2023-05-30
OpenSSL MEDIUM 6.5
CVE-2023-2650EPSS 75%

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications tha…

Fix: 1.0.2zh / 1.1.1u+
Fix from $1,600 2023-05-30
Mp4v2 MEDIUM 6.5
CVE-2023-33720

mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.

No fix yet
Fix from $1,600 2023-05-26
Android MEDIUM 5.5
CVE-2023-20930

In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lea…

Patch available
Fix from $1,600 2023-05-15
Android HIGH 7.8
CVE-2023-21110

In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local…

Patch available
Fix from $1,950 2023-05-15
Jerryscript MEDIUM 5.5
CVE-2023-31914

Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.

No fix yet
Fix from $1,600 2023-05-12
Froxlor HIGH 7.5
CVE-2023-2666

Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.

Fix: 2.0.16+
Fix from $1,950 2023-05-12
Rocket.chat HIGH 7.5
CVE-2023-28356

A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot l…

Fix: 6.0.0+
Fix from $1,950 2023-05-11
Boxo HIGH 7.5
CVE-2023-25568

Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is a…

Patch available
Fix from $1,950 2023-05-10
Ryzen 3945wx Firmware CRITICAL 9.8
CVE-2021-46760

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that ma…

Mitigation only
Fix from $2,300 2023-05-09
Gl S20 Firmware HIGH 7.5
CVE-2023-31472EPSS 20%

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the files…

Fix: 3.216+
Fix from $1,950 2023-05-09
macOS CRITICAL 9.1
CVE-2023-27958

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remo…

Fix: 11.7.5 / 12.6.4+
Fix from $2,300 2023-05-08
Rekor HIGH 7.5
CVE-2023-30551

Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused b…

Fix: 1.1.1+
Fix from $1,950 2023-05-08
Mq Appliance MEDIUM 5.9
CVE-2023-26285

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM …

Fix: 9.2.0.11 / 9.2.5.7+
Fix from $1,600 2023-05-05
Ebankit HIGH 7.5
CVE-2023-30455

An issue was discovered in ebankIT before 7. A Denial-of-Service attack is possible through the GET parameter EStatementsIds located on the /Controls…

Fix: 7.0+
Fix from $1,950 2023-04-28
Modsecurity HIGH 7.5
CVE-2023-28882

Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a seg…

Fix: 3.0.9+
Fix from $1,950 2023-04-28
Safer Payments HIGH 7.5
CVE-2023-27556

IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02 and 6.5.0.00 does not proper…

Fix: 6.3.1.04 / 6.4.2.03+
Fix from $1,950 2023-04-28
E1e G7f Firmware HIGH 7.5
CVE-2023-29779

Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send malicious Zigbee messages to a …

No fix yet
Fix from $1,950 2023-04-25
Jerryscript MEDIUM 5.5
CVE-2023-30406

Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.

No fix yet
Fix from $1,600 2023-04-24
Jerryscript MEDIUM 5.5
CVE-2023-30408

Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.

No fix yet
Fix from $1,600 2023-04-24
Rnp MEDIUM 5.3
CVE-2023-29479

Ribose RNP before 0.16.3 may hang when the input is malformed.

Fix: 0.16.3+
Fix from $1,600 2023-04-24
Mjs MEDIUM 5.5
CVE-2023-29570

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of S…

No fix yet
Fix from $1,600 2023-04-24
Bento4 MEDIUM 5.5
CVE-2023-29575

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.

No fix yet
Fix from $1,600 2023-04-21
M Files Server HIGH 7.5
CVE-2023-0383

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

Fix: 23.4.12528.1+
Fix from $1,950 2023-04-20