Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Debian Linux MEDIUM 6.5
CVE-2022-42315

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42316

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42317

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42318

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Emc Powerscale Onefs HIGH 7.5
CVE-2022-34439

Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unauthenticated …

Fix: after 9.4.0.5
Fix from $1,950 2022-10-21
Bento4 MEDIUM 5.5
CVE-2022-40885

Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.

No fix yet
Fix from $1,600 2022-10-19
Junos MEDIUM 5.5
CVE-2022-22240

An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protoco…

Fix: 20.4+
Fix from $1,600 2022-10-18
Junos Os Evolved HIGH 7.5
CVE-2022-22211

A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to …

Fix: 20.4+
Fix from $1,950 2022-10-18
Junos MEDIUM 6.5
CVE-2022-22226

In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devices an Uncontrolled Memory Allocation vulnerability in the Packet Forwarding Engine (PFE)…

Mitigation only
Fix from $1,600 2022-10-18
Go HIGH 7.5
CVE-2022-2879

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of…

Fix: 1.18.7 / 1.19.2+
Fix from $1,950 2022-10-14
Rdiffweb CRITICAL 9.8
CVE-2022-3439

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

Fix: 2.5.0+
Fix from $2,300 2022-10-14
Rdiffweb CRITICAL 9.8
CVE-2022-3456

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

Fix: 2.5.0+
Fix from $2,300 2022-10-13
Xapi MEDIUM 5.3
CVE-2022-33749

XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descriptor limit. This causes XAPI…

Patch available
Fix from $1,600 2022-10-11
Cics Tx MEDIUM 5.5
CVE-2022-34308

IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437.

Patch available
Fix from $1,600 2022-10-07
Nocodb MEDIUM 6.5
CVE-2022-3423

Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.

Fix: 0.92.0+
Fix from $1,600 2022-10-07
Debian Linux MEDIUM 6.5
CVE-2022-2929

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn l…

Fix: 4.1-esv+
Fix from $1,600 2022-10-07
Rdiffweb CRITICAL 9.8
CVE-2022-3273

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

Fix: after 2.4.10
Fix from $2,300 2022-10-06
Rdiffweb HIGH 7.5
CVE-2022-3371

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

Fix: after 2.4.9
Fix from $1,950 2022-09-30
Bento4 MEDIUM 5.5
CVE-2022-41845

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/A…

No fix yet
Fix from $1,600 2022-09-30
Bento4 MEDIUM 5.5
CVE-2022-41846

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBu…

No fix yet
Fix from $1,600 2022-09-30
Rdiffweb HIGH 7.5
CVE-2022-3364

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

Fix: after 2.4.9
Fix from $1,950 2022-09-29
Uclibc CRITICAL 9.8
CVE-2022-29503

A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can …

No fix yet
Fix from $2,300 2022-09-29
Rdiffweb HIGH 7.5
CVE-2022-3298

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

Fix: 2.4.8+
Fix from $1,950 2022-09-26
Rdiffweb HIGH 7.5
CVE-2022-3295

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

Fix: 2.4.8+
Fix from $1,950 2022-09-26
Swftools MEDIUM 5.5
CVE-2022-35089

SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.

No fix yet
Fix from $1,600 2022-09-21
Kafka HIGH 7.5
CVE-2022-34917

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated…

Fix: 2.8.2 / 3.0.2+
Fix from $1,950 2022-09-20
Mtower HIGH 7.5
CVE-2022-40762

A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application t…

Fix: after 0.3.0
Fix from $1,950 2022-09-16
Axum Core HIGH 7.5
CVE-2022-3212

<bytes::Bytes as axum_core::extract::FromRequest>::from_request would not, by default, set a limit for the size of the request body. That meant if a …

Fix: 0.2.8+
Fix from $1,950 2022-09-14
TYPO3 HIGH 7.5
CVE-2022-36104

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions requesting invalid or non-existing r…

Fix: after 11.5.15
Fix from $1,950 2022-09-13
Mattermost Server MEDIUM 6.5
CVE-2022-3147

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated…

Fix: 7.1.0+
Fix from $1,600 2022-09-09