All vulnerabilities
5184 / 5184
Sort
7.5
CVE-2023-44487ANC KEV
The HTTP/2 protocol allows a denial of service (server resource consumption) because request ca…
2023-01-01MicrosoftKEV
EPSS100.0%
pct 100
7.5
CVE-2023-50387AST
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) al…
2023-01-01MicrosoftPre-auth
EPSS100.0%
pct 99
5.0
CVE-2011-3192DEB
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2…
2011-01-01
EPSS98.9%
pct 99
5.3
CVE-2019-11478AST
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in …
2019-01-01Pre-auth
EPSS94.7%
pct 99
7.5
CVE-2024-31309ANC
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the…
2024-01-01Pre-auth
EPSS94.6%
pct 99
7.5
CVE-2023-45288ANC
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an…
2023-01-01Pre-auth
EPSS92.0%
pct 99
5.3
CVE-2019-11479AST
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This al…
2019-01-01Pre-auth
EPSS91.7%
pct 99
7.5
CVE-2024-27316ANC
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to gen…
2024-01-01Pre-auth
EPSS91.3%
pct 99
7.5
CVE-2020-9490AST
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' …
2020-01-01Pre-auth
EPSS89.7%
pct 99
5.3
CVE-2018-1000115DEB
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amp…
2018-01-01Pre-auth
EPSS88.6%
pct 99
4.3
CVE-2014-0221DEB
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.…
2014-01-01
EPSS87.9%
pct 99
7.5
CVE-2019-9515DEB
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial…
2019-01-01Pre-auth
EPSS87.8%
pct 99
7.5
CVE-2020-13935DEB
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 …
2020-01-01Pre-auth
EPSS87.6%
pct 99
7.5
CVE-2024-27983ANC
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount…
2024-01-01Pre-auth
EPSS87.2%
pct 99
7.5
CVE-2024-27919ANC
Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, the…
2024-01-01Pre-auth
EPSS86.7%
pct 99
5.3
CVE-2024-28182ANC
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 lib…
2024-01-01Pre-auth
EPSS85.0%
pct 99
4.3
CVE-2023-0921ANC
A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.…
2023-01-01
EPSS84.4%
pct 99
7.5
CVE-2017-14495DEB
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is …
2017-01-01Pre-auth
EPSS84.3%
pct 99
7.5
CVE-2019-9512DEB
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of s…
2019-01-01MicrosoftPre-auth
EPSS83.4%
pct 99
7.5
CVE-2024-2653DEB
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit u…
2024-01-01Pre-auth
EPSS83.2%
pct 99
7.5
CVE-2023-50868ANC
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is sk…
2023-01-01MicrosoftPre-auth
EPSS82.8%
pct 99
7.5
CVE-2019-9514DEB
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of…
2019-01-01MicrosoftPre-auth
EPSS82.8%
pct 99
7.5
CVE-2019-9513AST
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial o…
2019-01-01MicrosoftPre-auth
EPSS82.6%
pct 99
5.0
CVE-2009-2521CVE
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (…
2009-01-01
EPSS82.3%
pct 99
7.5
CVE-2017-8779DEB
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC throug…
2017-01-01Pre-auth
EPSS81.9%
pct 99
5.3
CVE-2011-5034CVE
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting …
2011-01-01Pre-auth
EPSS81.2%
pct 99
7.5
CVE-2023-28342CVE
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service a…
2023-01-01Pre-auth
EPSS78.6%
pct 99
5.3
CVE-2020-27223DEB
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty…
2020-01-01Pre-auth
EPSS78.0%
pct 99
6.5
CVE-2023-2650AST
Issue summary: Processing some specially crafted ASN.1 object identifiers or
data containing th…
2023-01-01Pre-auth
EPSS77.9%
pct 99
5.9
CVE-2021-21341DEB
XStream is a Java library to serialize objects to XML and back again. In XStream before version…
2021-01-01Pre-auth
EPSS77.9%
pct 99
7.5
CVE-2021-22883DEB
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service atta…
2021-01-01Pre-auth
EPSS77.4%
pct 99
7.5
CVE-2003-0714CVE
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to c…
2003-01-01
EPSS76.4%
pct 99
5.9
CVE-2016-2774DEB
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number…
2016-01-01Pre-auth
EPSS73.7%
pct 99
7.5
CVE-2018-5390AST
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue…
2018-01-01Pre-auth
EPSS73.5%
pct 99
5.0
CVE-2011-0762DEB
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authentica…
2011-01-01
EPSS73.3%
pct 99
7.5
CVE-2018-6389DEB
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource c…
2018-01-01Pre-auth
EPSS73.1%
pct 99
5.3
CVE-2019-10072DEB
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustio…
2019-01-01Pre-auth
EPSS73.0%
pct 99
7.5
CVE-2019-0199DEB
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted stre…
2019-01-01Pre-auth
EPSS72.9%
pct 99
5.3
CVE-2017-3144DEB
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to…
2017-01-01Pre-auth
EPSS72.7%
pct 99
3.7
CVE-2022-29885DEB
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0…
2022-01-01Pre-auth
EPSS71.7%
pct 99
Select a vulnerability on the left to open the preview.