Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2022-35220 Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A remote attacker with general… Team\+ Pro after 3.011.6.0.1 Fix from $1,6002022-08-02 MEDIUM 5.4 CVE-2022-35221 Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attack… Team\+ Pro after 3.011.6.0.1 Fix from $1,6002022-08-02 HIGH 7.5 CVE-2022-35922 Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memo… Fedora 0.26.5+ Fix from $1,9502022-08-01 MEDIUM 5.3 CVE-2022-35915 OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbo… Contracts 4.7.2+ Fix from $1,6002022-08-01 HIGH 7.5 CVE-2022-31184 Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has… Discourse after 2.8.6 Fix from $1,9502022-08-01 HIGH 7.5 CVE-2022-22212 An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allo… Junos Os Evolved Mitigation only Fix from $1,9502022-07-20 MEDIUM 6.5 CVE-2022-32958 A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size limit, to terminate other rec… Team\+ Pro after 3.011.6.0.1 Fix from $1,6002022-07-20 HIGH 7.5 CVE-2022-29286 Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishand… Pexip Infinity 28.0+ Fix from $1,9502022-07-17 MEDIUM 6.5 CVE-2022-2406 The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti… Mattermost after 6.5.1 Fix from $1,6002022-07-14 MEDIUM 6.5 CVE-2022-31075 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-31078 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-31079 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-31080 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 HIGH 7.5 CVE-2021-31645 An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit. Glftpd No fix yet Fix from $1,9502022-07-07 MEDIUM 6.5 CVE-2022-32206EPSS 32% curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with dif… Curl 7.84.0+ Fix from $1,6002022-07-07 HIGH 7.5 CVE-2022-34750 An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thousand characters. Unfortunatel… Mediawiki after 1.38.1 Fix from $1,9502022-06-28 MEDIUM 5.5 CVE-2021-40607 The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command. Gpac 2.0.0+ Fix from $1,6002022-06-28 MEDIUM 5.5 CVE-2021-40609 The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command. Gpac 2.0.0+ Fix from $1,6002022-06-28 HIGH 7.5 CVE-2021-40941 In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity in Ap4Array.h:172, as demo… Bento4 No fix yet Fix from $1,9502022-06-27 MEDIUM 6.5 CVE-2022-31016 Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption… Argo Cd 2.1.16 / 2.2.10+ Fix from $1,6002022-06-25 HIGH 7.5 CVE-2022-21952 A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote atta… Manager Server 4.1.46 / 4.2.37+ Fix from $1,9502022-06-22 HIGH 7.5 CVE-2022-22979 In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to ca… Spring Cloud Function 3.2.6+ Fix from $1,9502022-06-21 HIGH 7.8 CVE-2022-27871 Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the al… 3ds Max Mitigation only Fix from $1,9502022-06-21 MEDIUM 6.5 CVE-2022-2134 Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. Inventree 0.8.0+ Fix from $1,6002022-06-20 HIGH 7.5 CVE-2022-29863 OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation. Ua .net Standard Stack 1.4.368.58+ Fix from $1,9502022-06-16 MEDIUM 5.5 CVE-2022-20143 In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local de… Android Mitigation only Fix from $1,6002022-06-15 CRITICAL 9.1 CVE-2022-32559 An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. Couchbase Server 7.0.4+ Fix from $2,3002022-06-14 HIGH 7.5 CVE-2021-35096 Improper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect… Ar8035 Firmware Mitigation only Fix from $1,9502022-06-14 MEDIUM 5.5 CVE-2022-31285 An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h. Bento4 No fix yet Fix from $1,6002022-06-10 MEDIUM 5.5 CVE-2022-31287 An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp. Bento4 No fix yet Fix from $1,6002022-06-10