Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.6
CVE-2020-3566 KEV
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote att…
Ios Xr
Mitigation only
HIGH 7.4
CVE-2020-8203EPSS 5%
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Lodash
4.17.20+
MEDIUM 5.5
CVE-2020-15570
The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denia…
Whoopsie
after 0.2.69
HIGH 7.5
CVE-2020-12605
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or req…
Envoy
after 1.12.4
HIGH 7.5
CVE-2020-9494
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the …
Traffic Server
after 8.0.7
MEDIUM 5.3
CVE-2017-18899
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
Mattermost Server
4.0.5 / 4.1.1+
HIGH 7.5
CVE-2019-20880
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consump…
Mattermost Server
4.10.7 / 5.6.5+
HIGH 7.5
CVE-2019-20845
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack i…
Mattermost Server
5.18.0+
MEDIUM 6.5
CVE-2020-14405
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
Ubuntu Linux
0.9.12 / 3.2.1.0+
HIGH 7.5
CVE-2020-13250
HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to…
Consul
1.6.6 / 1.7.4+
HIGH 8.8
CVE-2020-0160
In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of s…
Android
Patch available
HIGH 7.5
CVE-2020-10705
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an ou…
Undertow
2.1.1+
HIGH 7.5
CVE-2019-20814
An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each page of an application level.
Phantompdf
8.3.12+
HIGH 7.5
CVE-2019-20818
An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created for each page of an applicati…
Phantompdf
9.7+
HIGH 7.5
CVE-2020-13114
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amoun…
Ubuntu Linux
0.6.22+
MEDIUM 5.3
CVE-2020-12697
The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.
Direct Mail
after 5.2.3
MEDIUM 6.5
CVE-2020-10717
A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant …
Qemu
5.0.1+
HIGH 7.5
CVE-2019-14941
SHAREit through 4.0.6.177 does not check the body length from the received packet header (which is used to allocate memory for the next set of data).…
Shareit
after 4.0.6.177
HIGH 7.5
CVE-2019-15234
SHAREit through 4.0.6.177 does not check the full message length from the received packet header (which is used to allocate memory for the next set o…
Shareit
after 4.0.6.177
HIGH 7.5
CVE-2020-11612EPSS 9%
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send …
Debian Linux
4.1.46+
MEDIUM 6.5
CVE-2020-8551
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via t…
Kubernetes
after 1.17.2
HIGH 7.5
CVE-2020-10364
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connectio…
Routeros
after 6.44.3
MEDIUM 6.5
CVE-2020-9345
An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of S…
Signopad Api\/web
3.1.1+
HIGH 7.5
CVE-2019-11939
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious …
Thrift
2020.03.16.00+
HIGH 7.5
CVE-2019-11938
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cl…
Thrift
2019.12.09.00+
HIGH 7.5
CVE-2019-3553
C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cli…
Thrift
2020.02.03.00+
HIGH 7.5
CVE-2020-8659
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.
Openshift Service Mesh
after 1.13.0
HIGH 7.5
CVE-2018-21035
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes…
Qt
after 5.14.1
HIGH 7.5
CVE-2019-4720
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote…
Websphere Application Server
20.0.0.2+
HIGH 7.5
CVE-2020-7218
HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial …
Nomad
0.10.3+