Vulnerability index

Browse CVEs

65 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Dpkg HIGH 8.2
CVE-2025-6297

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i…

Fix: 1.22.21+
Fix from $1,950 2025-07-01
Debian Linux HIGH 7.5
CVE-2024-27354

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate c…

Fix: 1.0.23 / 2.0.47+
Fix from $1,950 2024-03-01
Debian Linux HIGH 7.5
CVE-2024-27355

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a ce…

Fix: 1.0.23 / 2.0.47+
Fix from $1,950 2024-03-01
Debian Linux HIGH 7.5
CVE-2024-22201

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.…

Fix: 9.4.54 / 10.0.20+
Fix from $1,950 2024-02-26
Debian Linux HIGH 7.5
CVE-2024-24814

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Re…

Fix: after 2.4.15.1
Fix from $1,950 2024-02-13
Debian Linux MEDIUM 6.5
CVE-2022-37050

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PD…

Patch available
Fix from $1,600 2023-08-22
Debian Linux MEDIUM 6.5
CVE-2023-23009

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selec…

Patch available
Fix from $1,600 2023-02-21
Debian Linux HIGH 7.5
CVE-2022-30122

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

Fix: 2.0.9.1 / 2.1.4.1+
Fix from $1,950 2022-12-05
Debian Linux MEDIUM 6.5
CVE-2022-43238

Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attacker…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux HIGH 7.5
CVE-2022-3517

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand func…

Fix: 3.0.5+
Fix from $1,950 2022-10-17
Debian Linux HIGH 7.5
CVE-2022-41404

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via …

Fix: 0.5.4+
Fix from $1,950 2022-10-11
Debian Linux HIGH 7.5
CVE-2022-40150

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl…

Fix: after 1.4.0
Fix from $1,950 2022-09-16
Debian Linux HIGH 7.5
CVE-2020-29260

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

Patch available
Fix from $1,950 2022-09-02
Debian Linux HIGH 7.5
CVE-2021-20298

A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all me…

Fix: after 2.5.7
Fix from $1,950 2022-08-23
Debian Linux MEDIUM 5.5
CVE-2022-31030

containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause th…

Fix: 1.5.13 / 1.6.6+
Fix from $1,600 2022-06-09
Debian Linux HIGH 7.5
CVE-2022-26498EPSS 16%

An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files cou…

Fix: 18.11.2+
Fix from $1,950 2022-04-15
Debian Linux MEDIUM 5.3
CVE-2022-21360

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21366

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21340EPSS 8%

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21293EPSS 8%

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21299

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21277

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 6.5
CVE-2021-41229

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will …

No fix yet
Fix from $1,600 2021-11-12
Debian Linux MEDIUM 6.5
CVE-2021-3912

OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat…

Fix: 1.3.0+
Fix from $1,600 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3908

OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3909

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically…

Fix: 1.3.0+
Fix from $1,950 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-43173

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feedin…

Fix: 0.10.2+
Fix from $1,950 2021-11-09
Debian Linux HIGH 7.5
CVE-2021-37136EPSS 6%

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size u…

Fix: 2.2.4 / 4.1.68+
Fix from $1,950 2021-10-19
Debian Linux HIGH 7.5
CVE-2021-37137EPSS 7%

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved…

Fix: 4.1.68 / 12.0.0.4.6+
Fix from $1,950 2021-10-19
Debian Linux HIGH 7.5
CVE-2021-33623

The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the …

Fix: 3.0.1 / 4.0.1+
Fix from $1,950 2021-05-28