Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Vernemq HIGH 7.5
CVE-2021-33176

VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the hand…

Fix: 1.12.0+
Fix from $1,950 2021-06-08
Mintty HIGH 7.5
CVE-2021-28848

Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly…

Fix: 3.4.5+
Fix from $1,950 2021-06-03
Openshift Container Platform MEDIUM 6.5
CVE-2020-14336

A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an atta…

Mitigation only
Fix from $1,600 2021-06-02
Enterprise Linux MEDIUM 5.5
CVE-2021-3527

A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce th…

Fix: after 6.0.0
Fix from $1,600 2021-05-26
750 823 Firmware HIGH 7.5
CVE-2021-21000

On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial…

Mitigation only
Fix from $1,950 2021-05-24
Evm MEDIUM 6.5
CVE-2021-29511

evm is a pure Rust implementation of Ethereum Virtual Machine. Prior to the patch, when executing specific EVM opcodes related to memory operations t…

Fix: after 0.21.0
Fix from $1,600 2021-05-12
Simatic Wincc Runtime Advanced HIGH 7.5
CVE-2021-27383

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…

Fix: 15.1 / 16+
Fix from $1,950 2021-05-12
GitLab MEDIUM 5.3
CVE-2021-22210

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was…

Fix: 13.9.7 / 13.10.4+
Fix from $1,600 2021-05-06
Etherpad HIGH 7.5
CVE-2020-22785

Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with e…

Fix: 1.8.3+
Fix from $1,950 2021-04-28
Wireshark MEDIUM 6.5
CVE-2021-22207

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or cra…

Fix: after 3.4.4
Fix from $1,600 2021-04-23
Junos MEDIUM 6.5
CVE-2021-0242

A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker…

Mitigation only
Fix from $1,600 2021-04-22
Junos HIGH 7.5
CVE-2021-0261

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redire…

Mitigation only
Fix from $1,950 2021-04-22
Junos MEDIUM 6.5
CVE-2021-0224

A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote access subscriber (BRAS) nodes…

Mitigation only
Fix from $1,600 2021-04-22
Matrix Media Repo MEDIUM 6.5
CVE-2021-29453

matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle …

Fix: 1.2.7+
Fix from $1,600 2021-04-19
Sydent HIGH 7.5
CVE-2021-29430

Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send a…

Fix: 2.3.0+
Fix from $1,950 2021-04-15
Parse Duration HIGH 7.5
CVE-2021-29932

An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial of service (CPU and memory con…

Fix: after 2021-03-18
Fix from $1,950 2021-04-01
Groupware Core HIGH 7.5
CVE-2021-28994

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zaraf…

Fix: after 11.0.1
Fix from $1,950 2021-03-31
Debian Linux MEDIUM 5.5
CVE-2021-3478

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.5
CVE-2021-3479

There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Libass HIGH 8.8
CVE-2020-24994

Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote…

Fix: 0.15.0+
Fix from $1,950 2021-03-23
Pupnp HIGH 7.5
CVE-2021-28302

A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will rel…

Fix: 1.14.5+
Fix from $1,950 2021-03-12
Linux Kernel MEDIUM 6.5
CVE-2021-28038

An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of er…

Fix: 4.4.260 / 4.9.260+
Fix from $1,600 2021-03-05
Fedora MEDIUM 6.5
CVE-2021-21274

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.25.0+
Fix from $1,600 2021-02-26
Jackson Dataformats Binary HIGH 7.5
CVE-2020-28491

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchec…

Fix: 2.0.2 / 2.11.4+
Fix from $1,950 2021-02-18
Wireshark HIGH 7.5
CVE-2021-22174

Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

Fix: 3.4.3+
Fix from $1,950 2021-02-17
Linux Kernel MEDIUM 5.5
CVE-2021-26931

An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug…

Fix: after 5.10.16
Fix from $1,600 2021-02-17
Android MEDIUM 5.5
CVE-2021-0338

In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local de…

Patch available
Fix from $1,600 2021-02-10
Ac500 Cpu Firmware HIGH 8.6
CVE-2020-24685

An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability al…

Fix: 2.8.5+
Fix from $1,950 2021-02-09
Blaze HIGH 7.5
CVE-2021-21293

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are a…

Fix: 0.14.15+
Fix from $1,950 2021-02-02
Http4s HIGH 7.5
CVE-2021-21294

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have…

Fix: 0.21.17+
Fix from $1,950 2021-02-02