Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 8.6 CVE-2020-3566 KEV A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote att… Ios Xr Mitigation only Fix from $1,9502020-08-29 HIGH 7.4 CVE-2020-8203EPSS 5% Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. Lodash 4.17.20+ Fix from $1,9502020-07-15 MEDIUM 5.5 CVE-2020-15570 The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denia… Whoopsie after 0.2.69 Fix from $1,6002020-07-06 HIGH 7.5 CVE-2020-12605 Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or req… Envoy after 1.12.4 Fix from $1,9502020-07-01 HIGH 7.5 CVE-2020-9494 Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the … Traffic Server after 8.0.7 Fix from $1,9502020-06-24 MEDIUM 5.3 CVE-2017-18899 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting. Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 HIGH 7.5 CVE-2019-20880 An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consump… Mattermost Server 4.10.7 / 5.6.5+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20845 An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack i… Mattermost Server 5.18.0+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-14405 An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size. Ubuntu Linux 0.9.12 / 3.2.1.0+ Fix from $1,6002020-06-17 HIGH 7.5 CVE-2020-13250 HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to… Consul 1.6.6 / 1.7.4+ Fix from $1,9502020-06-11 HIGH 8.8 CVE-2020-0160 In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of s… Android Patch available Fix from $1,9502020-06-11 HIGH 7.5 CVE-2020-10705 A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an ou… Undertow 2.1.1+ Fix from $1,9502020-06-10 HIGH 7.5 CVE-2019-20814 An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each page of an application level. Phantompdf 8.3.12+ Fix from $1,9502020-06-04 HIGH 7.5 CVE-2019-20818 An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created for each page of an applicati… Phantompdf 9.7+ Fix from $1,9502020-06-04 HIGH 7.5 CVE-2020-13114 An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amoun… Ubuntu Linux 0.6.22+ Fix from $1,9502020-05-21 MEDIUM 5.3 CVE-2020-12697 The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries. Direct Mail after 5.2.3 Fix from $1,6002020-05-13 MEDIUM 6.5 CVE-2020-10717 A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant … Qemu 5.0.1+ Fix from $1,6002020-05-04 HIGH 7.5 CVE-2019-14941 SHAREit through 4.0.6.177 does not check the body length from the received packet header (which is used to allocate memory for the next set of data).… Shareit after 4.0.6.177 Fix from $1,9502020-04-27 HIGH 7.5 CVE-2019-15234 SHAREit through 4.0.6.177 does not check the full message length from the received packet header (which is used to allocate memory for the next set o… Shareit after 4.0.6.177 Fix from $1,9502020-04-27 HIGH 7.5 CVE-2020-11612EPSS 9% The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send … Debian Linux 4.1.46+ Fix from $1,9502020-04-07 MEDIUM 6.5 CVE-2020-8551 The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via t… Kubernetes after 1.17.2 Fix from $1,6002020-03-27 HIGH 7.5 CVE-2020-10364 The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connectio… Routeros after 6.44.3 Fix from $1,9502020-03-23 MEDIUM 6.5 CVE-2020-9345 An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of S… Signopad Api\/web 3.1.1+ Fix from $1,6002020-03-20 HIGH 7.5 CVE-2019-11939 Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious … Thrift 2020.03.16.00+ Fix from $1,9502020-03-18 HIGH 7.5 CVE-2019-11938 Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cl… Thrift 2019.12.09.00+ Fix from $1,9502020-03-10 HIGH 7.5 CVE-2019-3553 C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cli… Thrift 2020.02.03.00+ Fix from $1,9502020-03-10 HIGH 7.5 CVE-2020-8659 CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks. Openshift Service Mesh after 1.13.0 Fix from $1,9502020-03-04 HIGH 7.5 CVE-2018-21035 In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes… Qt after 5.14.1 Fix from $1,9502020-02-28 HIGH 7.5 CVE-2019-4720 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote… Websphere Application Server 20.0.0.2+ Fix from $1,9502020-01-31 HIGH 7.5 CVE-2020-7218 HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial … Nomad 0.10.3+ Fix from $1,9502020-01-31