| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections. |
| Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. Attackers can repeatedly submit malformed auth_context bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers. |
| RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connections to cause memory exhaustion and denial of service. The fix caps header-triggered speculative preallocation at 256 KiB. |
| Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversized parameters section. The AbstractPdb deserialization routine reads all remaining parameters into an unbounded list, causing uncontrolled heap growth that triggers an OutOfMemoryError which bypasses exception handling and crashes the application. |
| Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX.
An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint is publicly exposed. This issue affects Apache APISIX: from 1.3.0 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue. |
| Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop. |
| The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11. |
| ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1. |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1. |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0. |
| Issue summary: QUIC process may keep memory for QUIC packet
buffer for much longer period than necessary.
Impact summary: Remote peer can exploit this vulnerability
by sending maliciously crafted packets, making the local
QUIC stack to keep the memory for packet buffers allocated.
The time for which the memory remains allocated is entirely
under the control of the potentially malicious remote peer.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
Description: To save copy operation from the packet buffer to the
stream reassemble buffer the QUIC stack leaves the stream data
on the packet buffer waiting to be copied to a buffer provided
by the local receiving application. The QUIC stack releases
a reference to the packet buffer only after the data are copied
to the application buffer. This design is more efficient for
legitimate data transfers but enables an attacker to allocate a lot
more memory than actually required by the data kept in the receiving
stream buffer.
To mitigate the vulnerability, the QUIC stack now calculates
and monitors memory overhead for every stream. The memory overhead
for a single stream frame is calculated as a difference between the
size of the whole packet that carries the stream frame and the size
of the stream frame itself. The memory overhead for a single stream
frame is added to the total (cumulative) memory overhead QUIC stack
keeps for each stream. Once the cumulative memory overhead exceeds
64kB, the QUIC stack moves the stream frame data from the packet
buffer to the stream buffer, starting with the next packet received.
FIPS impact: no
The FIPS module is not affected as the QUIC implementation is outside of
the OpenSSL FIPS module boundary. |
| Issue summary: The QUIC stream reassembly algorithm performance deteriorates
progressively as packets are arriving out of order. The worst case has
a quadratic complexity proportional to the number of stream frames kept in
the buffer for the received stream data.
Impact summary: A remote QUIC peer that completes the handshake can create
a connection-scoped CPU pressure and potentially a Denial of Service using
compliant STREAM frames inside the advertised receive window, with low
attacker bandwidth.
CWE: CWE-407: Inefficient Algorithmic Complexity
Description: OpenSSL manages received QUIC stream fragments using a
doubly-linked list. While it optimizes for append operations (at the end of
the list), it falls back to a head-to-tail linear search for any fragment
that does not immediately follow the current `tail`.
By manipulating the sequence of offsets, an attacker can force the server
to perform O(n^2) operations, consuming excessive CPU time for the
QUIC process.
FIPS impact: no
The FIPS module is not affected as the QUIC implementation is outside of
the OpenSSL FIPS module boundary. |
| Issue summary: A certificate with many nameRelativeToCRLIssuer CRL
distribution points causes disproportionate heap growth when OpenSSL caches
X.509 extensions.
Impact summary: Receiving a crafted certificate from a malicious peer can lead
to significant memory pressure and possible Denial of Service in clients or
in servers that solicit client certificates.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
Description: A certificate or a set of certificates that fits under the limit for
size of certificates accepted from the peer (~100 KiB) can result in allocation
of several hundred MiB of resident memory on the receiving side
during a normal TLS handshake. This may be enough to crash the client or
server, if multiple concurrent connections lead to similarly large memory
allocations.
The fix postpones processing of the CRL distribution points extensions in
certificates to the time when the processed value is required for CRL processing.
This avoids keeping large memory allocations for a long time when such
certificates are received.
FIPS impact: no
The affected code is outside the FIPS module boundary. |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumption by exhausting the DRM VMA offset address space. A successful exploit of this vulnerability might lead to denial of service. |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generation by repeatedly invoking an interface that emits unrate-limited error messages. A successful exploit of this vulnerability might lead to denial of service. |
| Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue. |
| Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue. |
| The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than
four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not
against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one
missing check, both reachable before any authentication because TFTP has none.
The handler passes `nx_packet_length - 4` straight to FileX:
```c
/* addons/tftp/nxd_tftp_server.c:1863, 1889 */
status = nx_packet_copy(packet_ptr, &temp_ptr,
server_ptr -> nx_tftp_server_packet_pool_ptr, NX_WAIT_FOREVER);
...
fx_file_write(&(client_request_ptr -> nx_tftp_client_request_file),
packet_ptr -> nx_packet_prepend_ptr + 4,
packet_ptr -> nx_packet_length - 4);
```
`nx_packet_length` is the length of a chain, not of one contiguous buffer, so FileX copies past the
end of the first packet:
```
ERROR: AddressSanitizer: heap-buffer-overflow
READ of size 1280 at 0x621000001108 thread T5
#0 __interceptor_memcpy
#1 _fx_utility_memory_copy filex/common/src/fx_utility_memory_copy.c:78
0x621000001108 is 0 bytes to the right of 4104-byte region
```
Those bytes are written into the file the attacker is uploading, and a TFTP read request hands them
back, so this is a memory disclosure with a convenient retrieval channel.
The same datagram also wedges the server. `nx_packet_copy` at :1863 needs
ceil(nx_packet_length / pool_payload) packets and asks for them with NX_WAIT_FOREVER, so when the
attacker sizes the datagram beyond what the pool holds, the server thread suspends and never
returns. A liveness probe after one such datagram times out with the pool at 0 of 12 packets and
the server thread suspended, and no later client is served.
Reject `nx_packet_length > 4 + NX_TFTP_FILE_TRANSFER_MAX` in the DATA branch before either call,
and use a bounded wait rather than NX_WAIT_FOREVER for the copy. |
| Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.
Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD. |
| Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible. |