Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Ats2819p Firmware MEDIUM 6.5
CVE-2021-31787

The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allo…

Mitigation only
Fix from $1,600 2021-11-30
Fedora HIGH 8.6
CVE-2021-28706

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to inc…

Fix: 4.12+
Fix from $1,950 2021-11-24
Moddable HIGH 7.8
CVE-2021-29324

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

No fix yet
Fix from $1,950 2021-11-19
Moddable HIGH 7.8
CVE-2021-29329

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTre…

Patch available
Fix from $1,950 2021-11-19
Debian Linux MEDIUM 6.5
CVE-2021-3912

OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat…

Fix: 1.3.0+
Fix from $1,600 2021-11-11
GitLab MEDIUM 5.3
CVE-2021-39907

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in h…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.3
CVE-2021-39912

A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
Asyncos HIGH 7.5
CVE-2021-34741

A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, re…

Fix: 13.0.4+
Fix from $1,950 2021-11-04
Fortiportal HIGH 7.5
CVE-2021-36174

A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal before 6.0.6 may allow an attacker to…

Fix: 6.0.6+
Fix from $1,950 2021-11-02
Virtual Gpu MEDIUM 5.5
CVE-2021-1121

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among other vGPUs …

Fix: 8.9 / 11.6+
Fix from $1,600 2021-10-29
Harmonyos MEDIUM 5.5
CVE-2021-22461

A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability…

Mitigation only
Fix from $1,600 2021-10-28
Secure Firewall Management Center HIGH 7.5
CVE-2021-40114

Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthentica…

Fix: 2.9.18 / 6.4.0.12+
Fix from $1,950 2021-10-27
Parallels Desktop HIGH 7.8
CVE-2021-34854

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must firs…

Mitigation only
Fix from $1,950 2021-10-25
Versiondog HIGH 8.1
CVE-2021-38463

The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functio…

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog MEDIUM 6.5
CVE-2021-38465

The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by gene…

Fix: 8.0.0+
Fix from $1,600 2021-10-22
Modern Async HIGH 7.5
CVE-2021-41167

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affe…

Fix: 1.0.4+
Fix from $1,950 2021-10-20
Junos MEDIUM 5.3
CVE-2021-31369

On MX Series platforms with MS-MPC/MS-MIC, an Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows …

Fix: 17.4+
Fix from $1,600 2021-10-19
Ruggedcom Rox Mx5000 Firmware HIGH 7.5
CVE-2021-41546

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX…

Fix: 2.14.1+
Fix from $1,950 2021-10-12
Fedora HIGH 7.5
CVE-2021-41799

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&l…

Fix: 1.36.2+
Fix from $1,950 2021-10-11
Fedora MEDIUM 5.3
CVE-2021-41800

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions ca…

Fix: 1.36.2+
Fix from $1,600 2021-10-11
Ata 190 Firmware HIGH 8.8
CVE-2021-34710

Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack …

Mitigation only
Fix from $1,950 2021-10-06
Ata 190 Firmware HIGH 7.5
CVE-2021-34735

Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack …

Mitigation only
Fix from $1,950 2021-10-06
Streaming Engine MEDIUM 6.5
CVE-2021-35492

Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/v…

Fix: after 4.8.11
Fix from $1,600 2021-10-05
Redis HIGH 7.5
CVE-2021-32675EPSS 17%

Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates m…

Fix: 5.0.14 / 6.0.16+
Fix from $1,950 2021-10-04
Eclair CRITICAL 9.4
CVE-2021-41591

ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.

Fix: 0.6.3+
Fix from $2,300 2021-10-04
C Lightning CRITICAL 9.4
CVE-2021-41592

Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.

Fix: after 0.10.1
Fix from $2,300 2021-10-04
Lightning Network Daemon HIGH 8.6
CVE-2021-41593

Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure.

Fix: 0.11.0+
Fix from $1,950 2021-10-04
Meeting Connector HIGH 7.5
CVE-2021-34415

The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in…

Fix: 4.6.358.20210205+
Fix from $1,950 2021-09-27
Android MEDIUM 5.5
CVE-2021-0422

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit…

Mitigation only
Fix from $1,600 2021-09-27
Android MEDIUM 5.5
CVE-2021-0424

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit…

Mitigation only
Fix from $1,600 2021-09-27