CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2019-13926 HIGH
SCALANCE S602, S612, S623, S627-2M Firmware >=3.0 <4.1 - Denial of Service via Crafted Packets to Port 443
CVSS 7.5
CVE-2019-13925 HIGH
SCALANCE S602/S612/S623/S627-2M Firmware 3.0-4.1 - Denial of Service via Crafted Packets to Port 443
CVSS 7.5
CVE-2019-9674 HIGH
Python < 3.8 - Denial of Service via ZIP Bomb
CVSS 7.5
CVE-2019-20446 MEDIUM
librsvg < 2.46.2 - Denial of Service via Nested SVG Pattern Elements
CVSS 6.5
CVE-2019-5472 HIGH
GitLab < 11.11.6, 12.0.0-12.0.3, < 12.1.2 - Improper Privilege Management
CVSS 7.5
CVE-2019-16022 HIGH
Cisco IOS XR - Denial of Service via Malformed BGP EVPN Attributes
CVSS 8.6
CVE-2019-16020 HIGH
Cisco IOS XR - Unauthenticated Denial of Service via BGP EVPN Update Message Processing
CVSS 8.6
CVE-2019-16018 MEDIUM
Cisco IOS XR - Denial of Service via Malformed BGP EVPN Update Message
CVSS 6.5
CVE-2019-14888 HIGH
Undertow < 2.0.28 - Denial of Service via HTTPS Port
CVSS 7.5
CVE-2019-15961 HIGH
ClamAV < 0.101.4 - Unauthenticated Denial of Service via MIME Parsing Routines
CVSS 7.5
CVE-2019-20146 MEDIUM
GitLab 11.0-12.6 - Uncontrolled Resource Consumption
CVSS 5.3
CVE-2019-10775 HIGH
ecstatic < 4.1.3 - Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2019-20201 MEDIUM
ezxml 0.8.3-0.8.6 - Denial of Service via XML Entity Parsing
CVSS 6.5
CVE-2019-20176 HIGH
Pure-FTPd 1.0.49 - Denial of Service via Stack Exhaustion in listdir Function
CVSS 7.5
CVE-2019-6683 HIGH
BIG-IP 11.5.2-15.0.1.1 - Uncontrolled Resource Consumption via FastL4 Profile
CVSS 7.5
CVE-2019-6682 HIGH
BIG-IP ASM 11.5.2-15.0.1.1 - Uncontrolled Resource Consumption via HTTP Response
CVSS 7.5
CVE-2019-19922 MEDIUM
Linux Kernel < 5.3.9 - Denial of Service via Slice Expiration in CFS Quota
CVSS 5.5
CVE-2019-15584 MEDIUM
GitLab < 12.3.2, < 12.2.6, and < 12.1.10 - Denial of Service via Markdown Field Input Validation Bypass
CVSS 6.5
CVE-2019-16555 MEDIUM
Jenkins Build Failure Analyzer Plugin <1.24.1 - DoS
CVSS 6.5
CVE-2019-12420 HIGH
Apache SpamAssassin < 3.4.3 - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2019-16671 MEDIUM
Weidmueller IE-SW-VL05M <3.6.6, IE-SW-VL08MT <3.5.2, IE-SW-PL10M <3...
CVSS 6.5
CVE-2019-14901 CRITICAL
Linux Kernel 3.x.x-4.x.x < 4.18.0 - Heap Overflow in Marvell WiFi Chip Driver
CVSS 9.8
CVE-2019-6667 HIGH
BIG-IP 11.5.1-11.6.5 - Uncontrolled Resource Consumption in FIX Profile Traffic Processing
CVSS 7.5
CVE-2019-14867 HIGH
FreeIPA 4.6.0-4.6.6, 4.7.0-4.7.3, 4.8.0-4.8.2 - Unauthenticated Denial of Service via Kerberos Key Parsing
CVSS 8.8
CVE-2019-6477 HIGH
BIND 9.11.7-9.11.11 - Uncontrolled Resource Consumption via TCP Pipelining
CVSS 7.5
Details
Vulnerabilities 3,152
Exploit Likelihood High