Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Moodle MEDIUM 5.3
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which co…

Fix: 3.5.16 / 3.8.7+
Fix from $1,600 2021-01-28
Umbrella MEDIUM 5.3
CVE-2021-1350

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service.…

Mitigation only
Fix from $1,600 2021-01-20
Drawings Software Development Kit HIGH 7.8
CVE-2021-25173

An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when readin…

Fix: 10.4.1 / 13.1.0.1+
Fix from $1,950 2021-01-18
Junos HIGH 7.4
CVE-2021-0217

A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Series switches running Juniper Networks Junos OS wi…

No fix yet
Fix from $1,950 2021-01-15
Jenkins MEDIUM 6.5
CVE-2021-21607

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to r…

Fix: after 2.274
Fix from $1,600 2021-01-13
Virtual Gpu Manager HIGH 7.8
CVE-2021-1057

NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for w…

Fix: 8.6 / 11.3+
Fix from $1,950 2021-01-08
Socket.io Parser HIGH 7.5
CVE-2020-36049

socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach …

Fix: 3.4.1+
Fix from $1,950 2021-01-08
Ws Rs HIGH 7.5
CVE-2020-35896

An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumpt…

Fix: after 0.9.1
Fix from $1,950 2020-12-31
Factorytalk Linx HIGH 7.5
CVE-2020-5802EPSS 39%

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems mes…

Fix: after 6.11
Fix from $1,950 2020-12-29
Factorytalk Linx MEDIUM 5.5
CVE-2020-5806

An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messa…

Fix: after 6.11
Fix from $1,600 2020-12-29
Pure Ftpd HIGH 7.5
CVE-2020-35359

Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.

No fix yet
Fix from $1,950 2020-12-26
Arm Compiler HIGH 7.8
CVE-2020-24658

Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overflows in local arrays. When thi…

Fix: 5.06+
Fix from $1,950 2020-12-24
Debian Linux MEDIUM 6.0
CVE-2020-29486

An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node owne…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Xapi HIGH 7.5
CVE-2020-29487

An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are therefore watched by toolstack.…

Fix: 2020-12-15+
Fix from $1,950 2020-12-15
Fedora MEDIUM 6.2
CVE-2020-29567

An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated an…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.5
CVE-2020-29568

An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If t…

Fix: after 4.14.1
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.2
CVE-2020-29570

An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the contro…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Android MEDIUM 6.5
CVE-2020-27029

In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 5.5
CVE-2020-25652

A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket…

Fix: after 0.20.0
Fix from $1,600 2020-11-26
Debian Linux MEDIUM 5.5
CVE-2020-25650

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local gues…

Fix: after 0.20.0
Fix from $1,600 2020-11-25
Debian Linux HIGH 7.5
CVE-2020-8037

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

Fix: 10.14.6 / 10.15.7+
Fix from $1,950 2020-11-04
Wireshark HIGH 7.5
CVE-2020-28030

In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation o…

Fix: after 3.2.7
Fix from $1,950 2020-11-02
Identity Provider HIGH 7.5
CVE-2020-27978

Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java …

Fix: 3.4.6+
Fix from $1,950 2020-10-28
Enterprise Linux HIGH 7.5
CVE-2020-25648

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages,…

Fix: 3.58 / 9.2.6.0+
Fix from $1,950 2020-10-20
Vm Superio HIGH 7.5
CVE-2020-27173

In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). …

Fix: 0.1.1+
Fix from $1,950 2020-10-16
Ios Xr HIGH 8.6
CVE-2020-3569 KEV

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, r…

Fix: 6.5.2+
Fix from $1,950 2020-09-23
Android MEDIUM 6.5
CVE-2020-0353

In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additi…

Mitigation only
Fix from $1,600 2020-09-17
Keycloak HIGH 7.5
CVE-2020-10758

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak …

Fix: 11.0.1+
Fix from $1,950 2020-09-16
GitLab HIGH 7.5
CVE-2020-13306

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of serv…

Fix: 13.1.10 / 13.2.8+
Fix from $1,950 2020-09-14
Node Fetch MEDIUM 5.3
CVE-2020-15168

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was …

Fix: 2.6.1+
Fix from $1,600 2020-09-10