Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.5 CVE-2022-41727 An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a deni… Image 0.5.0+ Fix from $1,6002023-02-28 MEDIUM 6.5 CVE-2023-23916 An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, mea… Curl 7.88.0+ Fix from $1,6002023-02-23 HIGH 7.5 CVE-2022-31394 Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers … Hyper 0.14.19+ Fix from $1,9502023-02-21 HIGH 7.5 CVE-2023-26249 Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. S… Knot Resolver 5.6.0+ Fix from $1,9502023-02-21 HIGH 7.5 CVE-2021-32848 Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted searc… Octobox 2021-11-02+ Fix from $1,9502023-02-20 HIGH 7.5 CVE-2023-24998EPSS 47% Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin… Commons Fileupload 1.5+ Fix from $1,9502023-02-20 HIGH 7.5 CVE-2023-25656 notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation… Notation Go Mitigation only Fix from $1,9502023-02-20 MEDIUM 5.5 CVE-2023-24785 An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA fea… Peazip No fix yet Fix from $1,6002023-02-17 MEDIUM 5.5 CVE-2023-25153 containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of b… Containerd 1.5.18 / 1.6.18+ Fix from $1,6002023-02-16 HIGH 8.1 CVE-2023-0568 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv… PHP 8.0.28 / 8.1.16+ Fix from $1,9502023-02-16 CRITICAL 9.8 CVE-2023-25156 Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force … Kiwi Tcms 12.0+ Fix from $2,3002023-02-15 MEDIUM 5.9 CVE-2023-25171 Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-se… Kiwi Tcms 12.0+ Fix from $1,6002023-02-15 HIGH 7.5 CVE-2023-25578 Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing in `starlite` allows a potent… Starlite 1.51.2+ Fix from $1,9502023-02-15 HIGH 7.5 CVE-2023-25577 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited numbe… Werkzeug 2.2.3+ Fix from $1,9502023-02-14 HIGH 7.5 CVE-2023-25576 @fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/multipart may experience deni… Fastify Multipart 6.0.1 / 7.4.1+ Fix from $1,9502023-02-14 HIGH 7.5 CVE-2023-25193 hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back… Fedora after 6.0.0 Fix from $1,9502023-02-04 HIGH 7.5 CVE-2023-23969EPSS 47% In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repeti… Django 3.2.17 / 4.0.9+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-22323 In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when O… Big Ip Access Policy Manager 14.1.5.3 / 15.1.8.1+ Fix from $1,9502023-02-01 HIGH 7.5 CVE-2023-23846 Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS … Open5gs 2.4.13+ Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2023-22740 Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of R… Discourse after 3.0.0 Fix from $1,6002023-01-27 MEDIUM 6.5 CVE-2023-22739 Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) a… Discourse 3.0.1+ Fix from $1,6002023-01-26 MEDIUM 5.5 CVE-2022-20494 In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of servi… Android Mitigation only Fix from $1,6002023-01-26 HIGH 7.8 CVE-2022-20489 In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t… Android Mitigation only Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-20490 In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could le… Android Mitigation only Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-20492 In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t… Android Mitigation only Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-20456 In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead… Android Mitigation only Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-20047 A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenti… Webex Room Phone Firmware after 1.2.0 Fix from $1,6002023-01-20 HIGH 7.5 CVE-2021-36630 DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DOS attack… Sz 300 Firmware after 3.6.2 Fix from $1,9502023-01-18 MEDIUM 6.1 CVE-2023-22397 An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engine (PFE) on Juniper Networks J… Junos Os Evolved 20.4+ Fix from $1,6002023-01-13 HIGH 7.5 CVE-2023-22403 An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a net… Junos 20.2+ Fix from $1,9502023-01-13