Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Consul HIGH 7.5
CVE-2020-7219

HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial…

Fix: 1.6.2+
Fix from $1,950 2020-01-31
Bearftp HIGH 7.5
CVE-2020-8416EPSS 14%

IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.

Fix: 0.2.0+
Fix from $1,950 2020-01-29
Control For Beaglebone MEDIUM 6.5
CVE-2020-7052

CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condi…

Fix: 3.5.15.30+
Fix from $1,600 2020-01-24
Cryptacular HIGH 7.5
CVE-2020-7226

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during …

Fix: 1.1.4 / 1.2.4+
Fix from $1,950 2020-01-24
Libredwg MEDIUM 6.5
CVE-2020-6610

GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.

No fix yet
Fix from $1,600 2020-01-08
Matio MEDIUM 6.5
CVE-2019-20019

An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.

No fix yet
Fix from $1,600 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20009

An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private…

Fix: 0.9.3+
Fix from $1,600 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20012

An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.…

No fix yet
Fix from $1,600 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20013

An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spe…

Fix: 0.9.3+
Fix from $1,600 2019-12-27
Libredwg MEDIUM 6.5
CVE-2019-20015

An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in…

No fix yet
Fix from $1,600 2019-12-27
Libiec61850 MEDIUM 6.5
CVE-2019-19958

In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted…

No fix yet
Fix from $1,600 2019-12-24
Puma HIGH 7.5
CVE-2019-16770

In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of se…

Fix: 3.12.2 / 4.3.1+
Fix from $1,950 2019-12-05
Mcrouter HIGH 7.5
CVE-2019-11923

In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowin…

Fix: 0.41.0+
Fix from $1,950 2019-12-04
GitLab MEDIUM 6.5
CVE-2019-15593

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Is…

Patch available
Fix from $1,600 2019-11-22
Cxf MEDIUM 6.5
CVE-2019-12406EPSS 6%

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility o…

Fix: 3.2.11 / 3.3.4+
Fix from $1,600 2019-11-06
Miner HIGH 7.5
CVE-2019-6120

An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address allows remote attackers to sub…

Fix: 2.0.3.0+
Fix from $1,950 2019-11-06
Nest Cam Iq Indoor Firmware HIGH 7.5
CVE-2019-5043

An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can ca…

No fix yet
Fix from $1,950 2019-10-31
Traffic Server HIGH 7.5
CVE-2019-10079

Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting fra…

Fix: 7.1.7 / 8.0.4+
Fix from $1,950 2019-10-22
Icms HIGH 7.5
CVE-2019-17583

idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by …

Mitigation only
Fix from $1,950 2019-10-14
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5743EPSS 6%

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunabl…

Fix: after 14.1.1
Fix from $1,950 2019-10-09
Tomee HIGH 7.5
CVE-2019-17359EPSS 9%

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, vi…

Fix: after 3.0.2.1
Fix from $1,950 2019-10-08
Linux Kernel MEDIUM 6.5
CVE-2019-17351

An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a …

Fix: 5.2.3+
Fix from $1,600 2019-10-08
Pillow HIGH 7.5
CVE-2019-16865

An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amount…

Fix: 6.2.0+
Fix from $1,950 2019-10-04
Debian Linux MEDIUM 5.3
CVE-2019-15165

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

Fix: 1.9.1+
Fix from $1,600 2019-10-03
Ic3000 Industrial Compute Gateway Firmware MEDIUM 6.5
CVE-2019-12714

A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cau…

Fix: 1.1.1+
Fix from $1,600 2019-10-02
Pycharm HIGH 7.5
CVE-2019-14958

JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could l…

Fix: 2019.2+
Fix from $1,950 2019-10-02
Phantompdf HIGH 8.8
CVE-2019-5031EPSS 6%

An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially…

Fix: after 9.4.1.16828
Fix from $1,950 2019-10-02
Putty CRITICAL 9.8
CVE-2019-17067

PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incomi…

Fix: 0.73+
Fix from $2,300 2019-10-01
Android HIGH 8.8
CVE-2019-9291

In Bluetooth, there is a possible remote code execution due to an improper memory allocation. This could lead to remote code execution in Bluetooth w…

Mitigation only
Fix from $1,950 2019-09-27
Er X Firmware HIGH 7.5
CVE-2019-16889EPSS 5%

Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker…

Fix: 2.0.3+
Fix from $1,950 2019-09-25