Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2024-45626 Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu… James Server 3.7.6 / 3.8.2+ Fix from $1,9502025-02-06 MEDIUM 6.5 CVE-2024-53299 The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.… Wicket 9.19.0 / 10.3.0+ Fix from $1,6002025-01-23 HIGH 7.5 CVE-2025-23184 A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutput… Cxf 3.5.10 / 3.6.5+ Fix from $1,9502025-01-21 MEDIUM 5.3 CVE-2024-54677 Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue a… Tomcat 9.0.98 / 10.1.34+ Fix from $1,6002024-12-17 HIGH 7.5 CVE-2024-32007 An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of… Cxf 3.5.9 / 3.6.4+ Fix from $1,9502024-07-19 HIGH 7.5 CVE-2024-34750 Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomc… Tomcat 9.0.90 / 10.1.25+ Fix from $1,9502024-07-03 MEDIUM 6.5 CVE-2024-23952 This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be trig… Superset 2.1.3 / 3.0.2+ Fix from $1,6002024-02-14 MEDIUM 6.5 CVE-2023-46104 Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.… Superset 2.1.3 / 3.0.1+ Fix from $1,6002023-12-19 HIGH 7.5 CVE-2023-43622EPSS 71% An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP … HTTP Server 2.4.58+ Fix from $1,9502023-10-23 MEDIUM 5.5 CVE-2023-42503 Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common… Commons Compress 1.24.0+ Fix from $1,6002023-09-14 HIGH 8.1 CVE-2023-37379 Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed… Airflow 2.7.0+ Fix from $1,9502023-08-23 HIGH 7.5 CVE-2022-43766 Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP que… Iotdb after 0.13.2 Fix from $1,9502022-10-26 HIGH 7.5 CVE-2022-24294 A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul… Mxnet 1.9.1+ Fix from $1,9502022-07-24 HIGH 7.5 CVE-2022-26477 The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered wi… Systemds after 2.2.1 Fix from $1,9502022-06-27 HIGH 7.5 CVE-2022-29885EPSS 73% The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor in… Tomcat after 10.0.20 Fix from $1,9502022-05-12 CRITICAL 10.0 CVE-2021-44228 KEVEPSS 100% Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… Log4j 2.1.0 / 2.3.1+ Fix from $2,3002021-12-10 HIGH 7.5 CVE-2021-33580 User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression… Roller 6.0.2+ Fix from $1,9502021-08-18 HIGH 7.5 CVE-2021-30468EPSS 7% A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr… Cxf 3.3.11 / 3.4.4+ Fix from $1,9502021-06-16 HIGH 7.5 CVE-2021-22696EPSS 7% CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F… Cxf 3.3.10 / 3.4.3+ Fix from $1,9502021-04-02 HIGH 7.5 CVE-2021-21348EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-21341EPSS 78% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 MEDIUM 5.3 CVE-2020-27223EPSS 78% In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers … Nifi 9.4.36+ Fix from $1,6002021-02-26 HIGH 7.5 CVE-2020-13949EPSS 7% In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leadin… Hive 4.0.0+ Fix from $1,9502021-02-12 HIGH 7.5 CVE-2020-9481 Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack. Traffic Server after 8.0.6 Fix from $1,9502020-04-27 MEDIUM 5.5 CVE-2020-1950 A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. Tika after 1.23 Fix from $1,6002020-03-23 HIGH 7.5 CVE-2014-0212 qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors Qpid Cpp Mitigation only Fix from $1,9502019-12-13 HIGH 7.5 CVE-2019-12420EPSS 7% In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r… Spamassassin 3.4.3+ Fix from $1,9502019-12-12 HIGH 7.5 CVE-2019-9518EPSS 25% Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9511EPSS 60% Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9512EPSS 83% Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/… Traffic Server 8.16.1 / 10.16.3+ Fix from $1,9502019-08-13