Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Debian Linux HIGH 7.5
CVE-2025-47287

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo…

Fix: 6.5.0+
Fix from $1,950 2025-05-15
Debian Linux MEDIUM 5.3
CVE-2024-28182EPSS 85%

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbound…

Fix: 1.61.0+
Fix from $1,600 2024-04-04
Debian Linux MEDIUM 5.3
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients…

Fix: 4.1.108+
Fix from $1,600 2024-03-25
Debian Linux MEDIUM 6.8
CVE-2024-28102

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service att…

Fix: 1.5.6+
Fix from $1,600 2024-03-21
Debian Linux HIGH 7.5
CVE-2024-22201

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.…

Fix: 9.4.54 / 10.0.20+
Fix from $1,950 2024-02-26
Debian Linux HIGH 7.5
CVE-2023-2828

Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent…

Fix: after 9.19.13
Fix from $1,950 2023-06-21
Debian Linux HIGH 8.6
CVE-2022-42333

x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c…

Fix: after 4.17.0
Fix from $1,950 2023-03-21
Debian Linux MEDIUM 6.5
CVE-2022-42334

x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c…

Fix: after 4.17.0
Fix from $1,600 2023-03-21
Debian Linux MEDIUM 6.5
CVE-2022-42312

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42313

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42314

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42315

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42316

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42317

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42318

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-2929

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn l…

Fix: 4.1-esv+
Fix from $1,600 2022-10-07
Debian Linux HIGH 7.5
CVE-2022-21716

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is ab…

Fix: 22.2.0+
Fix from $1,950 2022-03-03
Debian Linux HIGH 7.5
CVE-2022-23837EPSS 5%

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system,…

Fix: 5.2.10 / 6.4.0+
Fix from $1,950 2022-01-21
Debian Linux MEDIUM 5.3
CVE-2022-21294

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 6.5
CVE-2021-3912

OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat…

Fix: 1.3.0+
Fix from $1,600 2021-11-11
Debian Linux MEDIUM 5.5
CVE-2021-3478

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.5
CVE-2021-3479

There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 6.0
CVE-2020-29486

An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node owne…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.5
CVE-2020-29568

An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If t…

Fix: after 4.14.1
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.2
CVE-2020-29570

An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the contro…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 5.5
CVE-2020-25652

A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket…

Fix: after 0.20.0
Fix from $1,600 2020-11-26
Debian Linux MEDIUM 5.5
CVE-2020-25650

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local gues…

Fix: after 0.20.0
Fix from $1,600 2020-11-25
Debian Linux HIGH 7.5
CVE-2020-8037

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

Fix: 10.14.6 / 10.15.7+
Fix from $1,950 2020-11-04
Debian Linux HIGH 7.5
CVE-2020-11612EPSS 9%

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send …

Fix: 4.1.46+
Fix from $1,950 2020-04-07
Debian Linux MEDIUM 5.3
CVE-2019-15165

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

Fix: 1.9.1+
Fix from $1,600 2019-10-03