Vulnerability index

Browse CVEs

63 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.5 CVE-2024-26308 Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 b… Commons Compress 1.26.0+ Fix from $1,6002024-02-19 MEDIUM 6.5 CVE-2023-42504 An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial… Superset 3.0.0+ Fix from $1,6002023-11-28 HIGH 7.5 CVE-2023-34396EPSS 5% Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro… Struts 2.5.31 / 6.1.2.1+ Fix from $1,9502023-06-14 MEDIUM 6.5 CVE-2023-34149EPSS 5% Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro… Struts 2.5.31 / 6.1.2.1+ Fix from $1,6002023-06-14 HIGH 7.5 CVE-2023-24998EPSS 47% Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin… Commons Fileupload 1.5+ Fix from $1,9502023-02-20 HIGH 7.5 CVE-2022-34917 A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated… Kafka 2.8.2 / 3.0.2+ Fix from $1,9502022-09-20 HIGH 7.5 CVE-2022-35724 It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin… Avro 0.14.0+ Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-36124 It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust ap… Avro 0.14.0+ Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-29404EPSS 6% In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no defau… HTTP Server after 2.4.53 Fix from $1,9502022-06-09 HIGH 7.5 CVE-2022-30522EPSS 90% If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m… HTTP Server Mitigation only Fix from $1,9502022-06-09 MEDIUM 5.5 CVE-2022-25169 The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. Tika 1.28.2 / 2.4.0+ Fix from $1,6002022-05-16 MEDIUM 5.5 CVE-2022-26336 A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read… Poi 5.2.1+ Fix from $1,6002022-03-04 HIGH 7.5 CVE-2022-23913 In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumptio… Artemis 2.19.1+ Fix from $1,9502022-02-04 HIGH 7.5 CVE-2021-43045 A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. Th… Avro 1.11.0+ Fix from $1,9502022-01-06 HIGH 7.5 CVE-2021-35516EPSS 12% When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error ev… Commons Compress after 18.3 Fix from $1,9502021-07-13 HIGH 7.5 CVE-2021-35517EPSS 11% When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error e… Commons Compress after 18.3 Fix from $1,9502021-07-13 MEDIUM 5.5 CVE-2021-31811 In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version … Pdfbox after 14.3.0 Fix from $1,6002021-06-12 HIGH 7.5 CVE-2020-9494 Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the … Traffic Server after 8.0.7 Fix from $1,9502020-06-24 MEDIUM 6.5 CVE-2019-12406EPSS 6% Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility o… Cxf 3.2.11 / 3.3.4+ Fix from $1,6002019-11-06 HIGH 7.5 CVE-2019-10079 Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting fra… Traffic Server 7.1.7 / 8.0.4+ Fix from $1,9502019-10-22 HIGH 7.5 CVE-2019-17359EPSS 9% The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, vi… Tomee after 3.0.2.1 Fix from $1,9502019-10-08 HIGH 7.5 CVE-2019-15544 An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls. Hbase 1.7.5 / 2.6.0+ Fix from $1,9502019-08-26 HIGH 7.5 CVE-2019-9518EPSS 25% Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9511EPSS 60% Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9514EPSS 83% Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9515EPSS 87% Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f… Traffic Server after 8.0.3 Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-9517EPSS 28% Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th… HTTP Server 2.4.40+ Fix from $1,9502019-08-13 MEDIUM 6.5 CVE-2019-9516EPSS 56% Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with … Traffic Server after 8.0.3 Fix from $1,6002019-08-13 HIGH 8.8 CVE-2019-10088 A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 o… Tika after 1.21 Fix from $1,9502019-08-02 HIGH 7.8 CVE-2019-10094 A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Ti… Tika after 1.21 Fix from $1,9502019-08-02