Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2021-33176 VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the hand… Vernemq 1.12.0+ Fix from $1,9502021-06-08 HIGH 7.5 CVE-2021-28848 Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly… Mintty 3.4.5+ Fix from $1,9502021-06-03 MEDIUM 6.5 CVE-2020-14336 A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an atta… Openshift Container Platform Mitigation only Fix from $1,6002021-06-02 MEDIUM 5.5 CVE-2021-3527 A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce th… Enterprise Linux after 6.0.0 Fix from $1,6002021-05-26 HIGH 7.5 CVE-2021-21000 On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial… 750 823 Firmware Mitigation only Fix from $1,9502021-05-24 MEDIUM 6.5 CVE-2021-29511 evm is a pure Rust implementation of Ethereum Virtual Machine. Prior to the patch, when executing specific EVM opcodes related to memory operations t… Evm after 0.21.0 Fix from $1,6002021-05-12 HIGH 7.5 CVE-2021-27383 A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM… Simatic Wincc Runtime Advanced 15.1 / 16+ Fix from $1,9502021-05-12 MEDIUM 5.3 CVE-2021-22210 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was… GitLab 13.9.7 / 13.10.4+ Fix from $1,6002021-05-06 HIGH 7.5 CVE-2020-22785 Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with e… Etherpad 1.8.3+ Fix from $1,9502021-04-28 MEDIUM 6.5 CVE-2021-22207 Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or cra… Wireshark after 3.4.4 Fix from $1,6002021-04-23 MEDIUM 6.5 CVE-2021-0242 A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker… Junos Mitigation only Fix from $1,6002021-04-22 HIGH 7.5 CVE-2021-0261 A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redire… Junos Mitigation only Fix from $1,9502021-04-22 MEDIUM 6.5 CVE-2021-0224 A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote access subscriber (BRAS) nodes… Junos Mitigation only Fix from $1,6002021-04-22 MEDIUM 6.5 CVE-2021-29453 matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle … Matrix Media Repo 1.2.7+ Fix from $1,6002021-04-19 HIGH 7.5 CVE-2021-29430 Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send a… Sydent 2.3.0+ Fix from $1,9502021-04-15 HIGH 7.5 CVE-2021-29932 An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial of service (CPU and memory con… Parse Duration after 2021-03-18 Fix from $1,9502021-04-01 HIGH 7.5 CVE-2021-28994 kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zaraf… Groupware Core after 11.0.1 Fix from $1,9502021-03-31 MEDIUM 5.5 CVE-2021-3478 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 5.5 CVE-2021-3479 There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 HIGH 8.8 CVE-2020-24994 Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote… Libass 0.15.0+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-28302 A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will rel… Pupnp 1.14.5+ Fix from $1,9502021-03-12 MEDIUM 6.5 CVE-2021-28038 An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of er… Linux Kernel 4.4.260 / 4.9.260+ Fix from $1,6002021-03-05 MEDIUM 6.5 CVE-2021-21274 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging… Fedora 1.25.0+ Fix from $1,6002021-02-26 HIGH 7.5 CVE-2020-28491 This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchec… Jackson Dataformats Binary 2.0.2 / 2.11.4+ Fix from $1,9502021-02-18 HIGH 7.5 CVE-2021-22174 Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file Wireshark 3.4.3+ Fix from $1,9502021-02-17 MEDIUM 5.5 CVE-2021-26931 An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug… Linux Kernel after 5.10.16 Fix from $1,6002021-02-17 MEDIUM 5.5 CVE-2021-0338 In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local de… Android Patch available Fix from $1,6002021-02-10 HIGH 8.6 CVE-2020-24685 An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability al… Ac500 Cpu Firmware 2.8.5+ Fix from $1,9502021-02-09 HIGH 7.5 CVE-2021-21293 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are a… Blaze 0.14.15+ Fix from $1,9502021-02-02 HIGH 7.5 CVE-2021-21294 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have… Http4s 0.21.17+ Fix from $1,9502021-02-02