Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2025-47287 Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo… Debian Linux 6.5.0+ Fix from $1,9502025-05-15 MEDIUM 5.3 CVE-2024-28182EPSS 85% nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbound… Debian Linux 1.61.0+ Fix from $1,6002024-04-04 MEDIUM 5.3 CVE-2024-29025 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients… Debian Linux 4.1.108+ Fix from $1,6002024-03-25 MEDIUM 6.8 CVE-2024-28102 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service att… Debian Linux 1.5.6+ Fix from $1,6002024-03-21 HIGH 7.5 CVE-2024-22201 Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.… Debian Linux 9.4.54 / 10.0.20+ Fix from $1,9502024-02-26 HIGH 7.5 CVE-2023-2828 Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent… Debian Linux after 9.19.13 Fix from $1,9502023-06-21 HIGH 8.6 CVE-2022-42333 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c… Debian Linux after 4.17.0 Fix from $1,9502023-03-21 MEDIUM 6.5 CVE-2022-42334 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c… Debian Linux after 4.17.0 Fix from $1,6002023-03-21 MEDIUM 6.5 CVE-2022-42312 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi… Debian Linux Patch available Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-42313 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi… Debian Linux Patch available Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-42314 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi… Debian Linux Patch available Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-42315 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi… Debian Linux Patch available Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-42316 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi… Debian Linux Patch available Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-42317 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi… Debian Linux Patch available Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-42318 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi… Debian Linux Patch available Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-2929 In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn l… Debian Linux 4.1-esv+ Fix from $1,6002022-10-07 HIGH 7.5 CVE-2022-21716 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is ab… Debian Linux 22.2.0+ Fix from $1,9502022-03-03 HIGH 7.5 CVE-2022-23837EPSS 5% In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system,… Debian Linux 5.2.10 / 6.4.0+ Fix from $1,9502022-01-21 MEDIUM 5.3 CVE-2022-21294 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are … Debian Linux after 15.0.5 Fix from $1,6002022-01-19 MEDIUM 6.5 CVE-2021-3912 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat… Debian Linux 1.3.0+ Fix from $1,6002021-11-11 MEDIUM 5.5 CVE-2021-3478 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 5.5 CVE-2021-3479 There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 6.0 CVE-2020-29486 An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node owne… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.5 CVE-2020-29568 An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If t… Debian Linux after 4.14.1 Fix from $1,6002020-12-15 MEDIUM 6.2 CVE-2020-29570 An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the contro… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-25652 A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket… Debian Linux after 0.20.0 Fix from $1,6002020-11-26 MEDIUM 5.5 CVE-2020-25650 A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local gues… Debian Linux after 0.20.0 Fix from $1,6002020-11-25 HIGH 7.5 CVE-2020-8037 The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. Debian Linux 10.14.6 / 10.15.7+ Fix from $1,9502020-11-04 HIGH 7.5 CVE-2020-11612EPSS 9% The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send … Debian Linux 4.1.46+ Fix from $1,9502020-04-07 MEDIUM 5.3 CVE-2019-15165 sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. Debian Linux 1.9.1+ Fix from $1,6002019-10-03