Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.5 CVE-2024-26816 In the Linux kernel, the following vulnerability has been resolved: x86, relocs: Ignore relocations in .notes section When building with CONFIG_XEN… Linux Kernel 4.19.311 / 5.4.273+ Fix from $1,6002024-04-10 MEDIUM 5.5 CVE-2024-26276 A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions <… Jt2go 14.2.0.12 / 14.3.0.9+ Fix from $1,6002024-04-09 HIGH 7.5 CVE-2024-0081 NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits o… Nemo Mitigation only Fix from $1,9502024-04-05 MEDIUM 6.5 CVE-2024-28949 Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences… Mattermost Server 8.1.11 / 9.3.3+ Fix from $1,6002024-04-05 HIGH 7.5 CVE-2024-27316EPSS 91% HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do… HTTP Server 2.4.59+ Fix from $1,9502024-04-04 HIGH 8.6 CVE-2024-30249 Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR1-20240330.101522-15` i… Mitigation only Fix from $1,9502024-04-04 HIGH 7.5 CVE-2024-27268 IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques… Websphere Application Server 24.0.0.5+ Fix from $1,9502024-04-04 MEDIUM 5.3 CVE-2024-28182EPSS 85% nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbound… Debian Linux 1.61.0+ Fix from $1,6002024-04-04 HIGH 7.5 CVE-2024-28871 LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading … Libhtp Patch available Fix from $1,9502024-04-04 HIGH 7.5 CVE-2024-22189 quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run out of memory sending a large… Patch available Fix from $1,9502024-04-04 MEDIUM 5.5 CVE-2024-26798 In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do_set_font() Commit a5a923038… Linux Kernel 5.15.151 / 6.1.81+ Fix from $1,6002024-04-04 HIGH 7.5 CVE-2024-28870 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Su… Suricata 6.0.17 / 7.0.4+ Fix from $1,9502024-04-03 MEDIUM 5.5 CVE-2024-26741 In the Linux kernel, the following vulnerability has been resolved: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().… Linux Kernel 6.1.80 / 6.6.19+ Fix from $1,6002024-04-03 MEDIUM 5.5 CVE-2024-26743 In the Linux kernel, the following vulnerability has been resolved: RDMA/qedr: Fix qedr_create_user_qp error flow Avoid the following warning by ma… Linux Kernel 5.10.211 / 5.15.150+ Fix from $1,6002024-04-03 MEDIUM 5.5 CVE-2024-26707 In the Linux kernel, the following vulnerability has been resolved: net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame() Syzkaller reported… Linux Kernel 5.10.210 / 5.15.149+ Fix from $1,6002024-04-03 MEDIUM 5.5 CVE-2024-26710 In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Limit KASAN thread size increase to 32KB KASAN is seen to increa… Linux Kernel 6.1.79 / 6.6.18+ Fix from $1,6002024-04-03 MEDIUM 5.5 CVE-2024-29086 in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow. Openharmony after 3.2.4 Fix from $1,6002024-04-02 MEDIUM 5.5 CVE-2024-26675 In the Linux kernel, the following vulnerability has been resolved: ppp_async: limit MRU to 64K syzbot triggered a warning [1] in __alloc_pages(): … Linux Kernel 4.19.307 / 5.4.269+ Fix from $1,6002024-04-02 HIGH 7.5 CVE-2024-22353 IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted reques… Websphere Application Server after 24.0.0.3 Fix from $1,9502024-03-31 MEDIUM 6.5 CVE-2024-2818 An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starti… GitLab 16.8.5 / 16.9.3+ Fix from $1,6002024-03-28 HIGH 7.5 CVE-2023-43768 An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memo… Couchbase Server 7.1.5+ Fix from $1,9502024-03-27 HIGH 7.5 CVE-2024-26577 VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet containing at least 10 digits i… Mitigation only Fix from $1,9502024-03-26 MEDIUM 6.5 CVE-2024-22436 A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service. No fix yet Fix from $1,6002024-03-26 MEDIUM 5.5 CVE-2024-26646 In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel alloca… Linux Kernel 6.1.76 / 6.6.15+ Fix from $1,6002024-03-26 MEDIUM 5.5 CVE-2023-52622 In the Linux kernel, the following vulnerability has been resolved: ext4: avoid online resizing failures due to oversized flex bg When we online re… Linux Kernel 4.19.307 / 5.4.269+ Fix from $1,6002024-03-26 MEDIUM 5.3 CVE-2024-29025 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients… Debian Linux 4.1.108+ Fix from $1,6002024-03-25 MEDIUM 5.5 CVE-2021-47170 In the Linux kernel, the following vulnerability has been resolved: USB: usbfs: Don't WARN about excessively large memory allocations Syzbot found … Linux Kernel 4.19.193 / 5.4.124+ Fix from $1,6002024-03-25 CRITICAL 9.8 CVE-2021-47137 In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory alloc… Linux Kernel 5.4.124 / 5.10.42+ Fix from $2,3002024-03-25 HIGH 7.5 CVE-2024-30156 Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an… Mitigation only Fix from $1,9502024-03-24 MEDIUM 6.5 CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An a… Tar 6.2.1+ Fix from $1,6002024-03-21