Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Db2 MEDIUM 5.1
CVE-2021-29763

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep runn…

Mitigation only
Fix from $1,600 2021-09-16
Big Ip Advanced Web Application Firewall MEDIUM 5.3
CVE-2021-23053

On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF o…

Fix: 13.1.3.6 / 14.1.3.1+
Fix from $1,600 2021-09-14
Richdocuments MEDIUM 5.3
CVE-2021-37629

Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS …

Fix: 3.8.4 / 4.2.1+
Fix from $1,600 2021-09-07
Covid 19 Contact Tracing MEDIUM 6.5
CVE-2021-33831

api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere…

Fix: after 2021-09-01
Fix from $1,600 2021-09-07
Workspace One Uem Console HIGH 7.5
CVE-2021-22029

VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause…

Fix: 20.1.0.33 / 20.5.0.51+
Fix from $1,950 2021-08-31
Bento4 HIGH 7.5
CVE-2018-10790

The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to…

No fix yet
Fix from $1,950 2021-08-25
GitLab MEDIUM 6.5
CVE-2021-22246

A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of servic…

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-08-20
Exiv2 MEDIUM 6.5
CVE-2020-18899

An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS…

No fix yet
Fix from $1,600 2021-08-19
Android MEDIUM 5.5
CVE-2021-0420

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit…

Mitigation only
Fix from $1,600 2021-08-18
Cobalt Strike HIGH 7.5
CVE-2021-36798

A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash t…

No fix yet
Fix from $1,950 2021-08-09
Application Delivery Controller Firmware HIGH 7.5
CVE-2021-22919

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Cit…

Fix: 10.2.9.b / 11.1-65.22+
Fix from $1,950 2021-08-05
Pdf2json MEDIUM 5.5
CVE-2020-19463

An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.

No fix yet
Fix from $1,600 2021-07-21
Pdf2json MEDIUM 5.5
CVE-2020-19464

An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .

No fix yet
Fix from $1,600 2021-07-21
Fedora MEDIUM 5.5
CVE-2021-33910EPSS 9%

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and all…

Fix: 246.15 / 247.8+
Fix from $1,600 2021-07-20
Junos HIGH 7.5
CVE-2021-0285

An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sendi…

Mitigation only
Fix from $1,950 2021-07-15
Secure External Authentication Server HIGH 7.5
CVE-2021-29725

IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resou…

Patch available
Fix from $1,950 2021-07-15
Dk Standard Ethernet Controller Evaluation Kit Firmware HIGH 7.5
CVE-2020-28400

Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be t…

Fix: 4.7 / 6.4+
Fix from $1,950 2021-07-13
Commons Compress HIGH 7.5
CVE-2021-35516EPSS 12%

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error ev…

Fix: after 18.3
Fix from $1,950 2021-07-13
Commons Compress HIGH 7.5
CVE-2021-35517EPSS 11%

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error e…

Fix: after 18.3
Fix from $1,950 2021-07-13
Grpc Swift HIGH 7.5
CVE-2021-36155

LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolle…

Mitigation only
Fix from $1,950 2021-07-09
Keycloak HIGH 7.5
CVE-2021-3637

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity …

Fix: 14.0.0+
Fix from $1,950 2021-07-09
Ilc1x0 Firmware HIGH 7.5
CVE-2021-33541

Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communicat…

Mitigation only
Fix from $1,950 2021-06-25
Wings MEDIUM 6.5
CVE-2021-32699

Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vu…

Fix: 1.4.4+
Fix from $1,600 2021-06-22
Ecns280 Td Firmware HIGH 7.5
CVE-2021-22363

There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the v…

No fix yet
Fix from $1,950 2021-06-22
Vfsjfilechooser2 HIGH 7.5
CVE-2021-29061

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the applica…

Fix: after 0.2.9
Fix from $1,950 2021-06-21
Fedora HIGH 7.5
CVE-2021-29063

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.

Fix: after 1.2.1
Fix from $1,950 2021-06-21
Is Svg HIGH 7.5
CVE-2021-29059

A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the applicat…

Fix: 4.3.0+
Fix from $1,950 2021-06-21
Color String MEDIUM 5.3
CVE-2021-29060

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application…

Fix: 1.5.5+
Fix from $1,600 2021-06-21
Pdfbox MEDIUM 5.5
CVE-2021-31811

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version …

Fix: after 14.3.0
Fix from $1,600 2021-06-12
Emq X Broker HIGH 7.5
CVE-2021-33175

EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of …

Fix: 4.2.8+
Fix from $1,950 2021-06-08