Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
GitLab HIGH 7.5
CVE-2019-15736

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be use…

Fix: 12.0.8 / 12.1.8+
Fix from $1,950 2019-09-16
GitLab HIGH 7.5
CVE-2019-15722

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can ex…

Fix: 12.0.8 / 12.1.8+
Fix from $1,950 2019-09-16
Hg100 Firmware HIGH 7.5
CVE-2019-11060

The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause …

Fix: after 1.05.12
Fix from $1,950 2019-08-29
Os Vif CRITICAL 9.1
CVE-2019-15753

In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ether…

Fix: 1.15.2+
Fix from $2,300 2019-08-28
Hbase HIGH 7.5
CVE-2019-15544

An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

Fix: 1.7.5 / 2.6.0+
Fix from $1,950 2019-08-26
Security Guardium Big Data Intelligence HIGH 7.5
CVE-2019-4338

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced …

Mitigation only
Fix from $1,950 2019-08-20
Fizz HIGH 7.5
CVE-2019-11924

A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in m…

Fix: after 2019.08.05.00
Fix from $1,950 2019-08-20
Envoy HIGH 7.5
CVE-2019-15225

In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote att…

Fix: after 1.11.1
Fix from $1,950 2019-08-19
Control For Beaglebone Sl HIGH 7.5
CVE-2019-9012

An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CO…

Fix: 3.5.14.20+
Fix from $1,950 2019-08-15
Traffic Server HIGH 7.5
CVE-2019-9518EPSS 25%

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9511EPSS 60%

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9514EPSS 83%

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9515EPSS 87%

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server MEDIUM 6.5
CVE-2019-9516EPSS 56%

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with …

Fix: after 8.0.3
Fix from $1,600 2019-08-13
HTTP Server HIGH 7.5
CVE-2019-9517EPSS 28%

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th…

Fix: 2.4.40+
Fix from $1,950 2019-08-13
Tika HIGH 8.8
CVE-2019-10088

A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 o…

Fix: after 1.21
Fix from $1,950 2019-08-02
Tika MEDIUM 6.5
CVE-2019-10093

In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs…

Fix: after 1.21
Fix from $1,600 2019-08-02
Tika HIGH 7.8
CVE-2019-10094

A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Ti…

Fix: after 1.21
Fix from $1,950 2019-08-02
Enterprise Linux Server Eus HIGH 7.5
CVE-2019-10171

It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would…

Fix: 1.4.0.17+
Fix from $1,950 2019-08-02
Routeros MEDIUM 6.5
CVE-2019-13954

Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remo…

Fix: 6.44.5+
Fix from $1,600 2019-07-26
Electric Fr Configurator2 MEDIUM 5.5
CVE-2019-10972

Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue …

Fix: after 1.16s
Fix from $1,600 2019-07-26
Libjpeg Turbo MEDIUM 5.5
CVE-2019-13960

In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and he…

Patch available
Fix from $1,600 2019-07-18
Lodash MEDIUM 6.5
CVE-2019-1010266

lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler.…

Fix: 4.17.11+
Fix from $1,600 2019-07-17
Routeros HIGH 7.5
CVE-2019-13074

A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device…

Fix: after 6.44.3
Fix from $1,950 2019-07-03
FreeBSD HIGH 7.5
CVE-2019-5599EPSS 5%

In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause…

Patch available
Fix from $1,950 2019-07-02
Fedora MEDIUM 6.5
CVE-2019-13112

A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Livezilla MEDIUM 5.9
CVE-2019-12940

LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth p…

Fix: 8.0.1.1+
Fix from $1,600 2019-06-24
Linux Kernel HIGH 7.5
CVE-2019-11478EPSS 95%

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling cer…

Fix: 4.4.182 / 4.9.182+
Fix from $1,950 2019-06-19
Linux Kernel HIGH 7.5
CVE-2019-11479EPSS 92%

Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues signi…

Fix: 4.4.182 / 4.9.182+
Fix from $1,950 2019-06-19
Somachine Basic HIGH 7.5
CVE-2018-7821

An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0…

Fix: 1.10.0.0+
Fix from $1,950 2019-05-22