Vulnerability index

Browse CVEs

65 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Debian Linux HIGH 7.5
CVE-2021-32918

An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memo…

Fix: 0.11.9+
Fix from $1,950 2021-05-13
Debian Linux MEDIUM 5.5
CVE-2021-3478

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.5
CVE-2021-3479

There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 6.5
CVE-2021-21375

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.10
Fix from $1,600 2021-03-10
Debian Linux HIGH 7.5
CVE-2020-35498EPSS 8%

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a special…

Fix: 2.5.12 / 2.6.10+
Fix from $1,950 2021-02-11
Debian Linux HIGH 7.5
CVE-2020-27813

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to …

Fix: 1.4.1+
Fix from $1,950 2020-12-02
Debian Linux HIGH 8.8
CVE-2020-15565

An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges…

Fix: after 4.13.1
Fix from $1,950 2020-07-07
Debian Linux HIGH 7.1
CVE-2020-14152

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing exces…

Fix: 9d+
Fix from $1,950 2020-06-15
Debian Linux HIGH 7.5
CVE-2020-11080EPSS 5%

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a mal…

Fix: 1.41.0 / 10.21.0+
Fix from $1,950 2020-06-03
Debian Linux HIGH 8.6
CVE-2020-8616EPSS 11%

A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, thro…

Fix: after 9.17.1
Fix from $1,950 2020-05-19
Debian Linux HIGH 7.5
CVE-2020-12662

Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NS…

Fix: 1.10.1+
Fix from $1,950 2020-05-19
Debian Linux HIGH 7.5
CVE-2011-4082

A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remot…

Fix: 0.9.8+
Fix from $1,950 2019-11-26
Debian Linux HIGH 7.5
CVE-2012-1572

OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space

Patch available
Fix from $1,950 2019-11-12
Debian Linux HIGH 7.5
CVE-2018-5819

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust availa…

Fix: 0.19.1+
Fix from $1,950 2019-02-20
Debian Linux HIGH 7.5
CVE-2018-16472

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inhe…

Fix: after 1.0.1
Fix from $1,950 2018-11-06
Debian Linux HIGH 7.5
CVE-2018-14648EPSS 6%

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An un…

Fix: 1.4.0.17+
Fix from $1,950 2018-09-28
Debian Linux MEDIUM 6.5
CVE-2018-17581

CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of se…

Patch available
Fix from $1,600 2018-09-28
Debian Linux HIGH 7.5
CVE-2018-17281EPSS 53%

There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 1…

Fix: after 15.6.0
Fix from $1,950 2018-09-24
Debian Linux HIGH 7.5
CVE-2018-16949

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded…

Fix: 1.6.23 / 1.8.2+
Fix from $1,950 2018-09-12
Debian Linux HIGH 7.5
CVE-2016-7068EPSS 7%

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacke…

Fix: 3.4.11 / 3.7.4+
Fix from $1,950 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7072EPSS 6%

An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of ser…

Fix: 3.4.11 / 4.0.2+
Fix from $1,950 2018-09-10
Debian Linux MEDIUM 6.5
CVE-2018-15469

An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an…

Fix: after 4.11.0
Fix from $1,600 2018-08-17
Debian Linux HIGH 7.5
CVE-2017-7651EPSS 5%

In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. …

Fix: after 1.4.14
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.5
CVE-2018-1064

libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor …

Fix: after 4.1.0
Fix from $1,950 2018-03-28
Debian Linux MEDIUM 6.5
CVE-2018-7876

In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers t…

No fix yet
Fix from $1,600 2018-03-08
Debian Linux MEDIUM 5.9
CVE-2017-15130

A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration…

Fix: 2.2.34+
Fix from $1,600 2018-03-02
Debian Linux MEDIUM 6.5
CVE-2018-7540

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L…

Fix: after 4.10.0
Fix from $1,600 2018-02-27
Debian Linux MEDIUM 5.5
CVE-2018-6616

In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerabili…

No fix yet
Fix from $1,600 2018-02-04
Debian Linux HIGH 7.5
CVE-2017-15132

A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by log…

Fix: after 2.2.33
Fix from $1,950 2018-01-25
Debian Linux MEDIUM 6.5
CVE-2018-5784

In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this v…

Patch available
Fix from $1,600 2018-01-19