Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Ios Xr HIGH 8.6
CVE-2020-3566 KEV

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote att…

Mitigation only
Fix from $1,950 2020-08-29
Lodash HIGH 7.4
CVE-2020-8203EPSS 5%

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Fix: 4.17.20+
Fix from $1,950 2020-07-15
Whoopsie MEDIUM 5.5
CVE-2020-15570

The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denia…

Fix: after 0.2.69
Fix from $1,600 2020-07-06
Envoy HIGH 7.5
CVE-2020-12605

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or req…

Fix: after 1.12.4
Fix from $1,950 2020-07-01
Traffic Server HIGH 7.5
CVE-2020-9494

Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the …

Fix: after 8.0.7
Fix from $1,950 2020-06-24
Mattermost Server MEDIUM 5.3
CVE-2017-18899

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20880

An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consump…

Fix: 4.10.7 / 5.6.5+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20845

An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack i…

Fix: 5.18.0+
Fix from $1,950 2020-06-19
Ubuntu Linux MEDIUM 6.5
CVE-2020-14405

An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.

Fix: 0.9.12 / 3.2.1.0+
Fix from $1,600 2020-06-17
Consul HIGH 7.5
CVE-2020-13250

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to…

Fix: 1.6.6 / 1.7.4+
Fix from $1,950 2020-06-11
Android HIGH 8.8
CVE-2020-0160

In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of s…

Patch available
Fix from $1,950 2020-06-11
Undertow HIGH 7.5
CVE-2020-10705

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an ou…

Fix: 2.1.1+
Fix from $1,950 2020-06-10
Phantompdf HIGH 7.5
CVE-2019-20814

An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each page of an application level.

Fix: 8.3.12+
Fix from $1,950 2020-06-04
Phantompdf HIGH 7.5
CVE-2019-20818

An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created for each page of an applicati…

Fix: 9.7+
Fix from $1,950 2020-06-04
Ubuntu Linux HIGH 7.5
CVE-2020-13114

An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amoun…

Fix: 0.6.22+
Fix from $1,950 2020-05-21
Direct Mail MEDIUM 5.3
CVE-2020-12697

The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.

Fix: after 5.2.3
Fix from $1,600 2020-05-13
Qemu MEDIUM 6.5
CVE-2020-10717

A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant …

Fix: 5.0.1+
Fix from $1,600 2020-05-04
Shareit HIGH 7.5
CVE-2019-14941

SHAREit through 4.0.6.177 does not check the body length from the received packet header (which is used to allocate memory for the next set of data).…

Fix: after 4.0.6.177
Fix from $1,950 2020-04-27
Shareit HIGH 7.5
CVE-2019-15234

SHAREit through 4.0.6.177 does not check the full message length from the received packet header (which is used to allocate memory for the next set o…

Fix: after 4.0.6.177
Fix from $1,950 2020-04-27
Debian Linux HIGH 7.5
CVE-2020-11612EPSS 9%

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send …

Fix: 4.1.46+
Fix from $1,950 2020-04-07
Kubernetes MEDIUM 6.5
CVE-2020-8551

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via t…

Fix: after 1.17.2
Fix from $1,600 2020-03-27
Routeros HIGH 7.5
CVE-2020-10364

The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connectio…

Fix: after 6.44.3
Fix from $1,950 2020-03-23
Signopad Api\/web MEDIUM 6.5
CVE-2020-9345

An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of S…

Fix: 3.1.1+
Fix from $1,600 2020-03-20
Thrift HIGH 7.5
CVE-2019-11939

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious …

Fix: 2020.03.16.00+
Fix from $1,950 2020-03-18
Thrift HIGH 7.5
CVE-2019-11938

Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cl…

Fix: 2019.12.09.00+
Fix from $1,950 2020-03-10
Thrift HIGH 7.5
CVE-2019-3553

C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cli…

Fix: 2020.02.03.00+
Fix from $1,950 2020-03-10
Openshift Service Mesh HIGH 7.5
CVE-2020-8659

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.

Fix: after 1.13.0
Fix from $1,950 2020-03-04
Qt HIGH 7.5
CVE-2018-21035

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes…

Fix: after 5.14.1
Fix from $1,950 2020-02-28
Websphere Application Server HIGH 7.5
CVE-2019-4720

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote…

Fix: 20.0.0.2+
Fix from $1,950 2020-01-31
Nomad HIGH 7.5
CVE-2020-7218

HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial …

Fix: 0.10.3+
Fix from $1,950 2020-01-31