Vulnerability index

Browse CVEs

63 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Commons Compress MEDIUM 5.5
CVE-2024-26308

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 b…

Fix: 1.26.0+
Fix from $1,600 2024-02-19
Superset MEDIUM 6.5
CVE-2023-42504

An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial…

Fix: 3.0.0+
Fix from $1,600 2023-11-28
Struts HIGH 7.5
CVE-2023-34396EPSS 5%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…

Fix: 2.5.31 / 6.1.2.1+
Fix from $1,950 2023-06-14
Struts MEDIUM 6.5
CVE-2023-34149EPSS 5%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…

Fix: 2.5.31 / 6.1.2.1+
Fix from $1,600 2023-06-14
Commons Fileupload HIGH 7.5
CVE-2023-24998EPSS 47%

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin…

Fix: 1.5+
Fix from $1,950 2023-02-20
Kafka HIGH 7.5
CVE-2022-34917

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated…

Fix: 2.8.2 / 3.0.2+
Fix from $1,950 2022-09-20
Avro HIGH 7.5
CVE-2022-35724

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Avro HIGH 7.5
CVE-2022-36124

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust ap…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
HTTP Server HIGH 7.5
CVE-2022-29404EPSS 6%

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no defau…

Fix: after 2.4.53
Fix from $1,950 2022-06-09
HTTP Server HIGH 7.5
CVE-2022-30522EPSS 90%

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m…

Mitigation only
Fix from $1,950 2022-06-09
Tika MEDIUM 5.5
CVE-2022-25169

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

Fix: 1.28.2 / 2.4.0+
Fix from $1,600 2022-05-16
Poi MEDIUM 5.5
CVE-2022-26336

A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read…

Fix: 5.2.1+
Fix from $1,600 2022-03-04
Artemis HIGH 7.5
CVE-2022-23913

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumptio…

Fix: 2.19.1+
Fix from $1,950 2022-02-04
Avro HIGH 7.5
CVE-2021-43045

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. Th…

Fix: 1.11.0+
Fix from $1,950 2022-01-06
Commons Compress HIGH 7.5
CVE-2021-35516EPSS 12%

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error ev…

Fix: after 18.3
Fix from $1,950 2021-07-13
Commons Compress HIGH 7.5
CVE-2021-35517EPSS 11%

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error e…

Fix: after 18.3
Fix from $1,950 2021-07-13
Pdfbox MEDIUM 5.5
CVE-2021-31811

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version …

Fix: after 14.3.0
Fix from $1,600 2021-06-12
Traffic Server HIGH 7.5
CVE-2020-9494

Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the …

Fix: after 8.0.7
Fix from $1,950 2020-06-24
Cxf MEDIUM 6.5
CVE-2019-12406EPSS 6%

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility o…

Fix: 3.2.11 / 3.3.4+
Fix from $1,600 2019-11-06
Traffic Server HIGH 7.5
CVE-2019-10079

Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting fra…

Fix: 7.1.7 / 8.0.4+
Fix from $1,950 2019-10-22
Tomee HIGH 7.5
CVE-2019-17359EPSS 9%

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, vi…

Fix: after 3.0.2.1
Fix from $1,950 2019-10-08
Hbase HIGH 7.5
CVE-2019-15544

An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

Fix: 1.7.5 / 2.6.0+
Fix from $1,950 2019-08-26
Traffic Server HIGH 7.5
CVE-2019-9518EPSS 25%

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9511EPSS 60%

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9514EPSS 83%

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9515EPSS 87%

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
HTTP Server HIGH 7.5
CVE-2019-9517EPSS 28%

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th…

Fix: 2.4.40+
Fix from $1,950 2019-08-13
Traffic Server MEDIUM 6.5
CVE-2019-9516EPSS 56%

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with …

Fix: after 8.0.3
Fix from $1,600 2019-08-13
Tika HIGH 8.8
CVE-2019-10088

A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 o…

Fix: after 1.21
Fix from $1,950 2019-08-02
Tika HIGH 7.8
CVE-2019-10094

A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Ti…

Fix: after 1.21
Fix from $1,950 2019-08-02