Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Debian Linux HIGH 7.5
CVE-2022-21716

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is ab…

Fix: 22.2.0+
Fix from $1,950 2022-03-03
Nomad HIGH 7.5
CVE-2022-24685

HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fi…

Fix: 1.1.12 / 1.2.6+
Fix from $1,950 2022-02-28
Metadata Extractor MEDIUM 5.5
CVE-2022-24614

When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an …

Fix: 2.18.0+
Fix from $1,600 2022-02-24
Sha256crypt HIGH 7.5
CVE-2016-20013

sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportiona…

Fix: after 0.6
Fix from $1,950 2022-02-19
Pexip Infinity HIGH 7.5
CVE-2022-23228

Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive resources, temporarily causing …

Fix: 27.0+
Fix from $1,950 2022-02-18
Cloud Foundation HIGH 7.5
CVE-2021-22050

ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to…

Fix: 3.11 / 4.4+
Fix from $1,950 2022-02-16
Client Golang HIGH 7.5
CVE-2022-21698EPSS 6%

client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTT…

Fix: 1.11.1+
Fix from $1,950 2022-02-15
Artemis HIGH 7.5
CVE-2022-23913

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumptio…

Fix: 2.19.1+
Fix from $1,950 2022-02-04
MongoDB HIGH 7.1
CVE-2021-32036

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to re…

Fix: 4.2.18 / 4.4.10+
Fix from $1,950 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-21732

Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack b…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Insydeh2o HIGH 8.2
CVE-2021-41840

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access…

Fix: 5.23.35 / 5.32.35+
Fix from $1,950 2022-02-03
Itext MEDIUM 6.5
CVE-2022-24196

iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allow…

Fix: 7.2.2+
Fix from $1,600 2022-02-01
Stormshield Network Security MEDIUM 5.3
CVE-2021-28096

An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would res…

Fix: 4.2.3+
Fix from $1,600 2022-01-27
Jerryscript HIGH 7.8
CVE-2021-44988

Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.

Patch available
Fix from $1,950 2022-01-25
Go HIGH 7.5
CVE-2021-39293EPSS 7%

In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a N…

Fix: 1.16.8 / 1.17.1+
Fix from $1,950 2022-01-24
Bingrep HIGH 7.5
CVE-2021-39480

Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).

No fix yet
Fix from $1,950 2022-01-21
Debian Linux HIGH 7.5
CVE-2022-23837EPSS 5%

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system,…

Fix: 5.2.10 / 6.4.0+
Fix from $1,950 2022-01-21
Debian Linux MEDIUM 5.3
CVE-2022-21294

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Junos HIGH 7.5
CVE-2022-22153

An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing dae…

Fix: 18.2+
Fix from $1,950 2022-01-19
Binaryen MEDIUM 5.5
CVE-2021-46050

A Stack Overflow vulnerability exists in Binaryen 103 via the printf_common function.

No fix yet
Fix from $1,600 2022-01-10
500 Series Firmware MEDIUM 6.5
CVE-2020-9059

Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to batt…

Mitigation only
Fix from $1,600 2022-01-10
Linux Kernel MEDIUM 6.5
CVE-2021-28714

Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains w…

Fix: 5.15.0+
Fix from $1,600 2022-01-06
Linux Kernel MEDIUM 6.5
CVE-2021-28715

Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains w…

Fix: 5.15.0+
Fix from $1,600 2022-01-06
Avro HIGH 7.5
CVE-2021-43045

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. Th…

Fix: 1.11.0+
Fix from $1,950 2022-01-06
Libming MEDIUM 6.5
CVE-2021-44590

In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could launch denial of service att…

No fix yet
Fix from $1,600 2022-01-06
Libming MEDIUM 6.5
CVE-2021-44591

In libming 0.4.8, the parseSWF_DEFINELOSSLESS2 function in util/parser.c lacks a boundary check that would lead to denial-of-service attacks via a cr…

No fix yet
Fix from $1,600 2022-01-06
Emui HIGH 7.5
CVE-2021-37111

There is a Memory leakage vulnerability in Smartphone.Successful exploitation of this vulnerability may cause memory exhaustion.

Fix: 2.0+
Fix from $1,950 2022-01-03
Ckb HIGH 7.5
CVE-2021-45699

An issue was discovered in the ckb crate before 0.40.0 for Rust. Remote attackers may be able to conduct a 51% attack against the Nervos CKB blockcha…

Fix: 0.40.0+
Fix from $1,950 2021-12-27
Atomix MEDIUM 6.5
CVE-2020-35210

A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack using Raft OpenSessionRequest…

Fix: after 3.1.5
Fix from $1,600 2021-12-16
Cbioportal HIGH 7.5
CVE-2021-38244

A regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to /ProteinArraySignificanceTest…

Fix: after 3.6.21
Fix from $1,950 2021-12-16