Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
James Server HIGH 7.5
CVE-2024-45626

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu…

Fix: 3.7.6 / 3.8.2+
Fix from $1,950 2025-02-06
Wicket MEDIUM 6.5
CVE-2024-53299

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.…

Fix: 9.19.0 / 10.3.0+
Fix from $1,600 2025-01-23
Cxf HIGH 7.5
CVE-2025-23184

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutput…

Fix: 3.5.10 / 3.6.5+
Fix from $1,950 2025-01-21
Tomcat MEDIUM 5.3
CVE-2024-54677

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue a…

Fix: 9.0.98 / 10.1.34+
Fix from $1,600 2024-12-17
Cxf HIGH 7.5
CVE-2024-32007

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of…

Fix: 3.5.9 / 3.6.4+
Fix from $1,950 2024-07-19
Tomcat HIGH 7.5
CVE-2024-34750

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomc…

Fix: 9.0.90 / 10.1.25+
Fix from $1,950 2024-07-03
Superset MEDIUM 6.5
CVE-2024-23952

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be trig…

Fix: 2.1.3 / 3.0.2+
Fix from $1,600 2024-02-14
Superset MEDIUM 6.5
CVE-2023-46104

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.…

Fix: 2.1.3 / 3.0.1+
Fix from $1,600 2023-12-19
HTTP Server HIGH 7.5
CVE-2023-43622EPSS 71%

An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP …

Fix: 2.4.58+
Fix from $1,950 2023-10-23
Commons Compress MEDIUM 5.5
CVE-2023-42503

Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common…

Fix: 1.24.0+
Fix from $1,600 2023-09-14
Airflow HIGH 8.1
CVE-2023-37379

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…

Fix: 2.7.0+
Fix from $1,950 2023-08-23
Iotdb HIGH 7.5
CVE-2022-43766

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP que…

Fix: after 0.13.2
Fix from $1,950 2022-10-26
Mxnet HIGH 7.5
CVE-2022-24294

A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul…

Fix: 1.9.1+
Fix from $1,950 2022-07-24
Systemds HIGH 7.5
CVE-2022-26477

The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered wi…

Fix: after 2.2.1
Fix from $1,950 2022-06-27
Tomcat HIGH 7.5
CVE-2022-29885EPSS 73%

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor in…

Fix: after 10.0.20
Fix from $1,950 2022-05-12
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Roller HIGH 7.5
CVE-2021-33580

User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression…

Fix: 6.0.2+
Fix from $1,950 2021-08-18
Cxf HIGH 7.5
CVE-2021-30468EPSS 7%

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr…

Fix: 3.3.11 / 3.4.4+
Fix from $1,950 2021-06-16
Cxf HIGH 7.5
CVE-2021-22696EPSS 7%

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…

Fix: 3.3.10 / 3.4.3+
Fix from $1,950 2021-04-02
Activemq HIGH 7.5
CVE-2021-21348EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq HIGH 7.5
CVE-2021-21341EPSS 78%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Nifi MEDIUM 5.3
CVE-2020-27223EPSS 78%

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers …

Fix: 9.4.36+
Fix from $1,600 2021-02-26
Hive HIGH 7.5
CVE-2020-13949EPSS 7%

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leadin…

Fix: 4.0.0+
Fix from $1,950 2021-02-12
Traffic Server HIGH 7.5
CVE-2020-9481

Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

Fix: after 8.0.6
Fix from $1,950 2020-04-27
Tika MEDIUM 5.5
CVE-2020-1950

A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

Fix: after 1.23
Fix from $1,600 2020-03-23
Qpid Cpp HIGH 7.5
CVE-2014-0212

qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors

Mitigation only
Fix from $1,950 2019-12-13
Spamassassin HIGH 7.5
CVE-2019-12420EPSS 7%

In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r…

Fix: 3.4.3+
Fix from $1,950 2019-12-12
Traffic Server HIGH 7.5
CVE-2019-9518EPSS 25%

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9511EPSS 60%

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9512EPSS 83%

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/…

Fix: 8.16.1 / 10.16.3+
Fix from $1,950 2019-08-13