Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2021-31787 The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allo… Ats2819p Firmware Mitigation only Fix from $1,6002021-11-30 HIGH 8.6 CVE-2021-28706 guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to inc… Fedora 4.12+ Fix from $1,9502021-11-24 HIGH 7.8 CVE-2021-29324 OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c. Moddable No fix yet Fix from $1,9502021-11-19 HIGH 7.8 CVE-2021-29329 OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTre… Moddable Patch available Fix from $1,9502021-11-19 MEDIUM 6.5 CVE-2021-3912 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat… Debian Linux 1.3.0+ Fix from $1,6002021-11-11 MEDIUM 5.3 CVE-2021-39907 A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in h… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 MEDIUM 5.3 CVE-2021-39912 A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 HIGH 7.5 CVE-2021-34741 A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, re… Asyncos 13.0.4+ Fix from $1,9502021-11-04 HIGH 7.5 CVE-2021-36174 A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal before 6.0.6 may allow an attacker to… Fortiportal 6.0.6+ Fix from $1,9502021-11-02 MEDIUM 5.5 CVE-2021-1121 NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among other vGPUs … Virtual Gpu 8.9 / 11.6+ Fix from $1,6002021-10-29 MEDIUM 5.5 CVE-2021-22461 A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability… Harmonyos Mitigation only Fix from $1,6002021-10-28 HIGH 7.5 CVE-2021-40114 Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthentica… Secure Firewall Management Center 2.9.18 / 6.4.0.12+ Fix from $1,9502021-10-27 HIGH 7.8 CVE-2021-34854 This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must firs… Parallels Desktop Mitigation only Fix from $1,9502021-10-25 HIGH 8.1 CVE-2021-38463 The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functio… Versiondog 8.0.0+ Fix from $1,9502021-10-22 MEDIUM 6.5 CVE-2021-38465 The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by gene… Versiondog 8.0.0+ Fix from $1,6002021-10-22 HIGH 7.5 CVE-2021-41167 modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affe… Modern Async 1.0.4+ Fix from $1,9502021-10-20 MEDIUM 5.3 CVE-2021-31369 On MX Series platforms with MS-MPC/MS-MIC, an Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows … Junos 17.4+ Fix from $1,6002021-10-19 HIGH 7.5 CVE-2021-41546 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX… Ruggedcom Rox Mx5000 Firmware 2.14.1+ Fix from $1,9502021-10-12 HIGH 7.5 CVE-2021-41799 MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&l… Fedora 1.36.2+ Fix from $1,9502021-10-11 MEDIUM 5.3 CVE-2021-41800 MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions ca… Fedora 1.36.2+ Fix from $1,6002021-10-11 HIGH 8.8 CVE-2021-34710 Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack … Ata 190 Firmware Mitigation only Fix from $1,9502021-10-06 HIGH 7.5 CVE-2021-34735 Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack … Ata 190 Firmware Mitigation only Fix from $1,9502021-10-06 MEDIUM 6.5 CVE-2021-35492 Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/v… Streaming Engine after 4.8.11 Fix from $1,6002021-10-05 HIGH 7.5 CVE-2021-32675EPSS 17% Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates m… Redis 5.0.14 / 6.0.16+ Fix from $1,9502021-10-04 CRITICAL 9.4 CVE-2021-41591 ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure. Eclair 0.6.3+ Fix from $2,3002021-10-04 CRITICAL 9.4 CVE-2021-41592 Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure. C Lightning after 0.10.1 Fix from $2,3002021-10-04 HIGH 8.6 CVE-2021-41593 Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure. Lightning Network Daemon 0.11.0+ Fix from $1,9502021-10-04 HIGH 7.5 CVE-2021-34415 The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in… Meeting Connector 4.6.358.20210205+ Fix from $1,9502021-09-27 MEDIUM 5.5 CVE-2021-0422 In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit… Android Mitigation only Fix from $1,6002021-09-27 MEDIUM 5.5 CVE-2021-0424 In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit… Android Mitigation only Fix from $1,6002021-09-27