Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2017-13763 ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited. Onos Mitigation only Fix from $1,9502017-08-30 MEDIUM 6.5 CVE-2017-12875 The WritePixelCachePixels function in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (CPU consumption) via a crafted file. Imagemagick Patch available Fix from $1,6002017-08-29 MEDIUM 5.5 CVE-2017-13716 The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of servi… Binutils Patch available Fix from $1,6002017-08-28 MEDIUM 6.5 CVE-2017-13133 In ImageMagick 7.0.6-8, the load_level function in coders/xcf.c lacks offset validation, which allows attackers to cause a denial of service (load_ti… Imagemagick Patch available Fix from $1,6002017-08-23 HIGH 7.8 CVE-2017-8253 In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel memory can potentially be overwritten if an invalid master is … Android Patch available Fix from $1,9502017-08-18 HIGH 7.5 CVE-2017-12944 The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to caus… Libtiff Mitigation only Fix from $1,9502017-08-18 MEDIUM 5.5 CVE-2017-0725 A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194. Android Patch available Fix from $1,6002017-08-09 MEDIUM 6.5 CVE-2017-12643 ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c. Debian Linux Patch available Fix from $1,6002017-08-07 MEDIUM 6.5 CVE-2017-12563 In ImageMagick 7.0.6-2, a memory exhaustion vulnerability was found in the function ReadPSDImage in coders/psd.c, which allows attackers to cause a d… Imagemagick Patch available Fix from $1,6002017-08-05 HIGH 7.5 CVE-2017-12429 In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a… Imagemagick Patch available Fix from $1,9502017-08-04 HIGH 7.5 CVE-2017-12430 In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a d… Imagemagick Patch available Fix from $1,9502017-08-04 MEDIUM 6.5 CVE-2017-12432 In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadPCXImage in coders/pcx.c, which allows attackers to cause a d… Imagemagick Patch available Fix from $1,6002017-08-04 HIGH 7.5 CVE-2017-12435 In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadSUNImage in coders/sun.c, which allows attackers to cause a d… Imagemagick Patch available Fix from $1,9502017-08-04 MEDIUM 5.5 CVE-2017-12144 In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a cr… Ytnef Mitigation only Fix from $1,6002017-08-02 MEDIUM 5.9 CVE-2017-12132 The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses f… Glibc after 2.25 Fix from $1,6002017-08-01 HIGH 7.5 CVE-2017-1227 IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906. Bigfix Platform Patch available Fix from $1,9502017-07-31 MEDIUM 6.5 CVE-2017-11525 The ReadCINImage function in coders/cin.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (… Imagemagick after 6.9.9-0 Fix from $1,6002017-07-23 HIGH 7.5 CVE-2017-11468 Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attack… Docker Registry after 2.6.1 Fix from $1,9502017-07-20 CRITICAL 9.8 CVE-2017-6713 A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access … Elastic Services Controller Mitigation only Fix from $2,3002017-07-06 MEDIUM 5.5 CVE-2017-9778 GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file ca… Gdb after 8.0 Fix from $1,6002017-06-21 CRITICAL 9.8 CVE-2017-6640EPSS 11% A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administr… Prime Data Center Network Manager Mitigation only Fix from $2,3002017-06-08 HIGH 7.5 CVE-2017-9350 In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors… Wireshark after 2.2.6 Fix from $1,9502017-06-02 HIGH 7.5 CVE-2017-6641 A vulnerability in the TCP connection handling functionality of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote at… Remote Expert Manager Mitigation only Fix from $1,9502017-05-22 HIGH 7.5 CVE-2017-6653 A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remo… Identity Services Engine Mitigation only Fix from $1,9502017-05-22 MEDIUM 5.5 CVE-2017-9039 GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related… Binutils Patch available Fix from $1,6002017-05-18 HIGH 7.0 CVE-2017-0612 An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application t… Linux Kernel Patch available Fix from $1,9502017-05-12 HIGH 7.5 CVE-2017-8779EPSS 81% rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size duri… Rpcbind after 1.4.3 Fix from $1,9502017-05-04 HIGH 7.5 CVE-2017-3555 Vulnerability in the Oracle iReceivables component of Oracle E-Business Suite (subcomponent: Self Registration). Supported versions that are affected… Ireceivables Mitigation only Fix from $1,9502017-04-24 HIGH 7.5 CVE-2017-7963 The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption… PHP after 7.1.4 Fix from $1,9502017-04-19 HIGH 7.5 CVE-2017-7696EPSS 36% SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in t… Sso Authentication Library Mitigation only Fix from $1,9502017-04-14