Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2024-26308
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 b…
Commons Compress
1.26.0+
MEDIUM 6.5
CVE-2023-42504
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial…
Superset
3.0.0+
HIGH 7.5
CVE-2023-34396EPSS 5%
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…
Struts
2.5.31 / 6.1.2.1+
MEDIUM 6.5
CVE-2023-34149EPSS 5%
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…
Struts
2.5.31 / 6.1.2.1+
HIGH 7.5
CVE-2023-24998EPSS 47%
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin…
Commons Fileupload
1.5+
HIGH 7.5
CVE-2022-34917
A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated…
Kafka
2.8.2 / 3.0.2+
HIGH 7.5
CVE-2022-35724
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin…
Avro
0.14.0+
HIGH 7.5
CVE-2022-36124
It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust ap…
Avro
0.14.0+
HIGH 7.5
CVE-2022-29404EPSS 6%
In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no defau…
HTTP Server
after 2.4.53
HIGH 7.5
CVE-2022-30522EPSS 90%
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m…
HTTP Server
Mitigation only
MEDIUM 5.5
CVE-2022-25169
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
Tika
1.28.2 / 2.4.0+
MEDIUM 5.5
CVE-2022-26336
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read…
Poi
5.2.1+
HIGH 7.5
CVE-2022-23913
In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumptio…
Artemis
2.19.1+
HIGH 7.5
CVE-2021-43045
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. Th…
Avro
1.11.0+
HIGH 7.5
CVE-2021-35516EPSS 12%
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error ev…
Commons Compress
after 18.3
HIGH 7.5
CVE-2021-35517EPSS 11%
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error e…
Commons Compress
after 18.3
MEDIUM 5.5
CVE-2021-31811
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version …
Pdfbox
after 14.3.0
HIGH 7.5
CVE-2020-9494
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the …
Traffic Server
after 8.0.7
MEDIUM 6.5
CVE-2019-12406EPSS 6%
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility o…
Cxf
3.2.11 / 3.3.4+
HIGH 7.5
CVE-2019-10079
Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting fra…
Traffic Server
7.1.7 / 8.0.4+
HIGH 7.5
CVE-2019-17359EPSS 9%
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, vi…
Tomee
after 3.0.2.1
HIGH 7.5
CVE-2019-15544
An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.
Hbase
1.7.5 / 2.6.0+
HIGH 7.5
CVE-2019-9518EPSS 25%
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra…
Traffic Server
after 8.0.3
HIGH 7.5
CVE-2019-9511EPSS 60%
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser…
Traffic Server
after 8.0.3
HIGH 7.5
CVE-2019-9514EPSS 83%
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s…
Traffic Server
after 8.0.3
HIGH 7.5
CVE-2019-9515EPSS 87%
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f…
Traffic Server
after 8.0.3
HIGH 7.5
CVE-2019-9517EPSS 28%
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th…
HTTP Server
2.4.40+
MEDIUM 6.5
CVE-2019-9516EPSS 56%
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with …
Traffic Server
after 8.0.3
HIGH 8.8
CVE-2019-10088
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 o…
Tika
after 1.21
HIGH 7.8
CVE-2019-10094
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Ti…
Tika
after 1.21