Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-1644
A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to …
Iot Field Network Director
Mitigation only
HIGH 7.5
CVE-2019-0010
An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an…
Junos
Mitigation only
MEDIUM 5.3
CVE-2019-0005
On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This i…
Junos
Mitigation only
MEDIUM 6.5
CVE-2018-16846
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
Ceph
13.2.4+
HIGH 7.8
CVE-2018-16865
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when m…
Enterprise Linux Desktop
Patch available
HIGH 7.8
CVE-2018-16864
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a…
Enterprise Linux Desktop
Patch available
HIGH 8.6
CVE-2018-15460
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthentic…
Asyncos
11.0.2-044_md / 11.1.2-023_md+
HIGH 7.5
CVE-2018-15458
A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction with remote authentication, c…
Secure Firewall Management Center
Mitigation only
MEDIUM 6.5
CVE-2018-20659
An issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive memory allocation when called …
Bento4
No fix yet
MEDIUM 6.5
CVE-2018-20652
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could…
Tinyexr
No fix yet
HIGH 7.5
CVE-2018-20421
Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory…
Go Ethereum
No fix yet
MEDIUM 6.5
CVE-2018-20095
An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocatio…
Bento4
No fix yet
HIGH 7.5
CVE-2018-1779
IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payloa…
Api Connect
after 2018.3.7
MEDIUM 6.5
CVE-2018-14660
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated…
Virtualization Host
after 4.1.4
MEDIUM 6.8
CVE-2018-15399
A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could …
Adaptive Security Appliance Software
Mitigation only
MEDIUM 6.5
CVE-2018-15404
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, …
Unified Computing System Director
Mitigation only
HIGH 7.5
CVE-2018-15383
A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defen…
Firepower Threat Defense
Mitigation only
HIGH 7.4
CVE-2018-15373
A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauth…
iOS
Mitigation only
HIGH 7.5
CVE-2018-1647
IBM QRadar Incident Forensics 7.2 and 7.3 does not properly restrict the size or amount of resources requested which could allow an unauthenticated u…
Qradar Incident Forensics
after 7.3.1
MEDIUM 6.5
CVE-2018-16645
There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11,…
Ubuntu Linux
Patch available
MEDIUM 6.3
CVE-2018-10908
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image…
Virtualization
4.20.37+
HIGH 7.5
CVE-2016-9578
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send …
Debian Linux
0.13.90+
MEDIUM 5.5
CVE-2017-2587
A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.
Netpbm
10.61.00+
MEDIUM 5.5
CVE-2018-13033
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (exc…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2018-12934
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OO…
Binutils
No fix yet
HIGH 7.5
CVE-2018-0358
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, rem…
Telepresence Video Communication Server
Mitigation only
HIGH 7.5
CVE-2017-5388
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of tim…
Firefox
51.0+
HIGH 7.5
CVE-2018-3737
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Sshpk
after 1.13.1
MEDIUM 5.5
CVE-2018-3738
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
Protobufjs
after 6.8.5
HIGH 7.5
CVE-2018-3711
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very l…
Fastify
0.38.0+