Vulnerabilities (CVE)

Filtered by CWE-400
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0671 1 Redhat 1 Vscode-xml 2022-02-26 6.4 MEDIUM 9.1 CRITICAL
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
CVE-2013-20004 1 Starwindsoftware 1 Iscsi San 2022-02-11 7.5 HIGH 9.8 CRITICAL
StarWind iSCSI SAN before 6.0 build 2013-03-20 allows a memory leak.
CVE-2020-7700 1 Php.js Project 1 Php.js 2021-07-21 7.5 HIGH 9.8 CRITICAL
All versions of phpjs are vulnerable to Prototype Pollution via parse_str.
CVE-2020-7703 1 Nis-utils Project 1 Nis-utils 2021-07-21 7.5 HIGH 9.8 CRITICAL
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
CVE-2020-35858 1 Prost Project 1 Prost 2021-07-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the prost crate before 0.6.1 for Rust. There is stack consumption via a crafted message, causing a denial of service (e.g., x86) or possibly remote code execution (e.g., ARM).
CVE-2020-7702 1 Templ8 Project 1 Templ8 2021-07-21 7.5 HIGH 9.8 CRITICAL
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
CVE-2020-7701 1 Springtree 1 Madlib-object-utils 2021-07-21 7.5 HIGH 9.8 CRITICAL
madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
CVE-2020-28448 1 Multi-ini Project 1 Multi-ini 2021-07-21 7.5 HIGH 9.8 CRITICAL
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
CVE-2017-9104 2 Gnu, Opensuse 2 Adns, Leap 2020-07-02 7.5 HIGH 9.8 CRITICAL
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
CVE-2019-10747 1 Set-value Project 1 Set-value 2019-10-29 7.5 HIGH 9.8 CRITICAL
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.
CVE-2019-10750 1 Deeply Project 1 Deeply 2019-10-08 7.5 HIGH 9.8 CRITICAL
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
CVE-2017-1000378 1 Netbsd 1 Netbsd 2019-10-03 7.5 HIGH 9.8 CRITICAL
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.
CVE-2019-2259 1 Qualcomm 70 Msm8909w, Msm8909w Firmware, Msm8996au and 67 more 2019-06-18 10.0 HIGH 9.8 CRITICAL
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130
CVE-2018-11936 1 Qualcomm 56 Mdm9206, Mdm9206 Firmware, Mdm9607 and 53 more 2019-05-28 10.0 HIGH 9.8 CRITICAL
Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads to out of bound memory access. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9379, QCA9886, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 820, SD 820A, SD 835, SDX20, SDX24, Snapdragon_High_Med_2016
CVE-2018-19282 1 Rockwellautomation 2 Powerflex 525 Ac Drives, Powerflex 525 Ac Drives Firmware 2019-04-09 10.0 HIGH 9.8 CRITICAL
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a way that it does not accept new connections, but keeps the current connections active, which can prevent legitimate users from recovering control.
CVE-2017-9119 2 Netapp, Php 3 Clustered Data Ontap, Storage Automation Store, Php 2019-03-19 7.5 HIGH 9.8 CRITICAL
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
CVE-2015-4412 1 Bson Project 1 Bson 2018-03-13 7.5 HIGH 9.8 CRITICAL
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.