Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.3 CVE-2021-20185 It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which co… Moodle 3.5.16 / 3.8.7+ Fix from $1,6002021-01-28 MEDIUM 5.3 CVE-2021-1350 A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service.… Umbrella Mitigation only Fix from $1,6002021-01-20 HIGH 7.8 CVE-2021-25173 An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when readin… Drawings Software Development Kit 10.4.1 / 13.1.0.1+ Fix from $1,9502021-01-18 HIGH 7.4 CVE-2021-0217 A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Series switches running Juniper Networks Junos OS wi… Junos No fix yet Fix from $1,9502021-01-15 MEDIUM 6.5 CVE-2021-21607 Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to r… Jenkins after 2.274 Fix from $1,6002021-01-13 HIGH 7.8 CVE-2021-1057 NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for w… Virtual Gpu Manager 8.6 / 11.3+ Fix from $1,9502021-01-08 HIGH 7.5 CVE-2020-36049 socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach … Socket.io Parser 3.4.1+ Fix from $1,9502021-01-08 HIGH 7.5 CVE-2020-35896 An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumpt… Ws Rs after 0.9.1 Fix from $1,9502020-12-31 HIGH 7.5 CVE-2020-5802EPSS 39% An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems mes… Factorytalk Linx after 6.11 Fix from $1,9502020-12-29 MEDIUM 5.5 CVE-2020-5806 An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messa… Factorytalk Linx after 6.11 Fix from $1,6002020-12-29 HIGH 7.5 CVE-2020-35359 Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit. Pure Ftpd No fix yet Fix from $1,9502020-12-26 HIGH 7.8 CVE-2020-24658 Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overflows in local arrays. When thi… Arm Compiler 5.06+ Fix from $1,9502020-12-24 MEDIUM 6.0 CVE-2020-29486 An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node owne… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 HIGH 7.5 CVE-2020-29487 An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are therefore watched by toolstack.… Xapi 2020-12-15+ Fix from $1,9502020-12-15 MEDIUM 6.2 CVE-2020-29567 An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated an… Fedora after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.5 CVE-2020-29568 An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If t… Debian Linux after 4.14.1 Fix from $1,6002020-12-15 MEDIUM 6.2 CVE-2020-29570 An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the contro… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.5 CVE-2020-27029 In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no addi… Android Mitigation only Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-25652 A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket… Debian Linux after 0.20.0 Fix from $1,6002020-11-26 MEDIUM 5.5 CVE-2020-25650 A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local gues… Debian Linux after 0.20.0 Fix from $1,6002020-11-25 HIGH 7.5 CVE-2020-8037 The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. Debian Linux 10.14.6 / 10.15.7+ Fix from $1,9502020-11-04 HIGH 7.5 CVE-2020-28030 In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation o… Wireshark after 3.2.7 Fix from $1,9502020-11-02 HIGH 7.5 CVE-2020-27978 Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java … Identity Provider 3.4.6+ Fix from $1,9502020-10-28 HIGH 7.5 CVE-2020-25648 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages,… Enterprise Linux 3.58 / 9.2.6.0+ Fix from $1,9502020-10-20 HIGH 7.5 CVE-2020-27173 In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). … Vm Superio 0.1.1+ Fix from $1,9502020-10-16 HIGH 8.6 CVE-2020-3569 KEV Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, r… Ios Xr 6.5.2+ Fix from $1,9502020-09-23 MEDIUM 6.5 CVE-2020-0353 In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additi… Android Mitigation only Fix from $1,6002020-09-17 HIGH 7.5 CVE-2020-10758 A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak … Keycloak 11.0.1+ Fix from $1,9502020-09-16 HIGH 7.5 CVE-2020-13306 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of serv… GitLab 13.1.10 / 13.2.8+ Fix from $1,9502020-09-14 MEDIUM 5.3 CVE-2020-15168 node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was … Node Fetch 2.6.1+ Fix from $1,6002020-09-10