CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2018-20030 HIGH
libexif 0.6.21 - Denial of Service via EXIF Tag Processing
CVSS 7.5
CVE-2018-16492 CRITICAL
extend <2.0.2, 3.0.0-3.0.2 - Prototype Pollution
CVSS 9.8
CVE-2018-16491 CRITICAL
node.extend <1.1.7 - Prototype Pollution
CVSS 9.8
CVE-2018-16490 HIGH
mpath < 0.5.1 - Prototype Pollution
CVSS 7.5
CVE-2018-16489 CRITICAL
just-extend < 4.0.0 - Prototype Pollution via Function Property Injection
CVSS 9.8
CVE-2018-16487 MEDIUM
lodash < 4.17.11 - Prototype Pollution via merge, mergeWith, and defaultsDeep Functions
CVSS 5.6
CVE-2018-16486 CRITICAL
defaults-deep <=0.2.4 - Prototype Pollution
CVSS 9.8
CVE-2018-17189 MEDIUM
Apache HTTP Server <= 2.4.37 - Denial of Service via Slow Loris HTTP/2 Request
CVSS 5.3
CVE-2018-20699 MEDIUM
Docker Engine < 18.09 - Denial of Service via Large Integer in CPUSet Parameters
CVSS 4.9
CVE-2018-15464 MEDIUM
Cisco ASR 900 Series Software - Unauthenticated Partial Denial of Service via Broadcast Packet Flood
CVSS 5.8
CVE-2018-6347 HIGH
Proxygen < 2018.12.31.00 - Denial of Service via HTTP/2 Header/Trailer Parsing
CVSS 7.5
CVE-2018-6346 HIGH
Proxygen < 2018.12.31.00 - Denial of Service via Invalid HTTP2 Priority Settings
CVSS 7.5
CVE-2018-6335 HIGH
HHVM < 3.21.10 - Denial of Service via Malformed HTTP/2 Frame
CVSS 7.5
CVE-2018-20543 MEDIUM
libxsmm - Denial of Service via Excessive Memory Allocation in CSC Reader
CVSS 6.5
CVE-2018-20502 MEDIUM
Bento4 1.5.1-627 - Uncontrolled Resource Consumption in AP4_HvccAtom::Create
CVSS 6.5
CVE-2018-19871 MEDIUM
Qt < 5.11.3 - Uncontrolled Resource Consumption in QTgaFile
CVSS 6.5
CVE-2018-18960 MEDIUM
Epson WorkForce WF-2861 Firmware <=10.52 Uncontrolled Resource Consumption via SNMP
CVSS 5.9
CVE-2018-1000872 MEDIUM
PyKMIP < 0.8.0 - Denial of Service via Socket Exhaustion
CVSS 6.5
CVE-2018-20186 MEDIUM
Bento4 1.5.1-627 - Memory Corruption
CVSS 6.5
CVE-2018-20169 MEDIUM
Linux kernel <4.19.9 - Buffer Overflow
CVSS 6.8
CVE-2018-6707 LOW
McAfee Agent 5.0.0-5.0.6, 5.5.0, 5.5.1 - Denial of Service via Resource Depletion
CVSS 3.7
CVE-2018-13815 HIGH
SIMATIC S7-1200 and S7-1500 < V2.6 - Unauthenticated Denial of Service via TCP Port 102 Connection Exhaustion
CVSS 7.5
CVE-2018-19881 MEDIUM
Artifex MuPDF 1.14.0 - Denial of Service via Crafted SVG File
CVSS 5.5
CVE-2018-17159 HIGH
FreeBSD < 11.2 - Unauthenticated Resource Exhaustion via READDIRPLUS NFS Request
CVSS 7.5
CVE-2018-19838 MEDIUM
libsass < 3.5.5 - Denial of Service via Recursive AST Operator Expansion
CVSS 6.5
Details
Vulnerabilities 3,152
Exploit Likelihood High