Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Milo HIGH 7.5
CVE-2022-25897

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory co…

Fix: 0.6.8+
Fix from $1,950 2022-09-08
Helm HIGH 7.5
CVE-2022-36049

Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allow…

Fix: 0.23.0 / 0.32.0+
Fix from $1,950 2022-09-07
Libraw MEDIUM 5.5
CVE-2020-35534

In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 fi…

Patch available
Fix from $1,600 2022-09-01
Helm MEDIUM 6.5
CVE-2022-36055

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input …

Fix: 3.9.4+
Fix from $1,600 2022-09-01
Wolfssl MEDIUM 5.9
CVE-2022-38153

An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle…

Patch available
Fix from $1,600 2022-08-31
Cimg MEDIUM 5.5
CVE-2022-1325

A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible…

Fix: 3.1.0+
Fix from $1,600 2022-08-31
Linux Kernel MEDIUM 5.5
CVE-2022-0480

A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limi…

Fix: 5.15+
Fix from $1,600 2022-08-29
Integration Camel K HIGH 7.5
CVE-2022-0084

A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. …

Fix: 3.8.7+
Fix from $1,950 2022-08-26
Linux Kernel MEDIUM 5.5
CVE-2021-3669

A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to…

Fix: 2.7+
Fix from $1,600 2022-08-26
Linux Kernel MEDIUM 5.5
CVE-2021-3759

A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function…

Mitigation only
Fix from $1,600 2022-08-23
Fedora HIGH 7.5
CVE-2022-25761

The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on …

Fix: 1.2.5+
Fix from $1,950 2022-08-23
Opcua HIGH 7.5
CVE-2022-25888

The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single sess…

Patch available
Fix from $1,950 2022-08-23
Freeopcua HIGH 7.5
CVE-2022-24298

All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption…

Mitigation only
Fix from $1,950 2022-08-23
Opc Ua Stack HIGH 7.5
CVE-2022-24381

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per…

Mitigation only
Fix from $1,950 2022-08-23
Node Opcua HIGH 7.5
CVE-2022-25231

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA…

Fix: 2.74.0+
Fix from $1,950 2022-08-23
Asyncua HIGH 7.5
CVE-2022-25304

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of…

Mitigation only
Fix from $1,950 2022-08-23
Swfmill MEDIUM 5.5
CVE-2022-36146

SWFMill commit 53d7690 was discovered to contain a memory allocation issue via operator new[](unsigned long) at asan_new_delete.cpp.

Fix: after 0.3.6
Fix from $1,600 2022-08-16
Tifig MEDIUM 5.5
CVE-2022-36155

tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cpp.

No fix yet
Fix from $1,600 2022-08-16
Swftools MEDIUM 5.5
CVE-2022-35107

SWFTools commit 772e55a2 was discovered to contain a stack overflow via vfprintf at /stdio-common/vfprintf.c.

No fix yet
Fix from $1,600 2022-08-16
Swftools MEDIUM 5.5
CVE-2022-35111

SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer::StackDepotNode::hash(__sanitizer::StackTrace const&) at /sanitiz…

No fix yet
Fix from $1,600 2022-08-16
Pngdec MEDIUM 6.5
CVE-2022-35009

PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp.

No fix yet
Fix from $1,600 2022-08-16
Moodle HIGH 7.5
CVE-2020-14322

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of ser…

Fix: 3.5.13 / 3.7.7+
Fix from $1,950 2022-08-16
Mtower HIGH 7.5
CVE-2022-38155

TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated…

Fix: after 0.3.0
Fix from $1,950 2022-08-11
Scalance M 800 Firmware HIGH 7.5
CVE-2022-36324

Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TC…

No fix yet
Fix from $1,950 2022-08-10
Avro HIGH 7.5
CVE-2022-35724

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Avro HIGH 7.5
CVE-2022-36124

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust ap…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Nextcloud Server MEDIUM 5.3
CVE-2022-31118

Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find if federated sharing is being …

Fix: 22.2.9 / 23.0.6+
Fix from $1,600 2022-08-04
Triplecross HIGH 7.5
CVE-2022-35505

A segmentation fault in TripleCross v0.1.0 occurs when sending a control command from the client to the server. This occurs because there is no limit…

No fix yet
Fix from $1,950 2022-08-03
Health Insurance Web Service Component MEDIUM 5.5
CVE-2022-35218

The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length…

Mitigation only
Fix from $1,600 2022-08-02
Health Insurance Web Service Component MEDIUM 5.5
CVE-2022-35219

The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter.…

Mitigation only
Fix from $1,600 2022-08-02