CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2018-19837 MEDIUM
libsass < 3.5.5 - Denial of Service via Modulo Operator Parsing
CVSS 6.5
CVE-2018-6332 MEDIUM
HHVM < 3.21.7 - Denial of Service via Proxygen HTTP2 Settings Handling
CVSS 5.9
CVE-2018-14626 MEDIUM
PowerDNS Authoritative Server <4.1.5-Recursor <4.1.4 - DoS
CVSS 5.3
CVE-2018-10851 MEDIUM
PowerDNS Authoritative 3.3.0-4.1.4 and Recursor 3.2-4.1.4 - Denial of Service via Malformed Record Parsing
CVSS 5.3
CVE-2018-12122 HIGH
Node.js <6.15.0, 8.14.0, 10.14.0, 11.3.0 - DoS
CVSS 7.5
CVE-2018-12121 HIGH
Node.js <6.15.0,8.14.0,10.14.0,11.3.0 - DoS
CVSS 7.5
CVE-2018-16853 HIGH
Samba 4.7.0-4.7.11 - Denial of Service in MIT Kerberos AD DC Configuration
CVSS 7.5
CVE-2018-14629 MEDIUM
Samba 4.0.0-4.7.11 - Denial of Service via LDAP CNAME Loop Recursion
CVSS 6.5
CVE-2018-0700 HIGH
YukiWiki < 2.1.3 - Denial of Service via Resource Consumption
CVSS 7.5
CVE-2018-16470 HIGH
Rack < 2.0.6 - Denial of Service via Multipart Parser
CVSS 7.5
CVE-2018-15772 HIGH
Dell EMC RecoverPoint < 5.1.2.1 & RecoverPoint for VMs < 5.2.0.2 - Resource Consumption via Boxmgmt CLI
CVSS 7.1
CVE-2018-1786 MEDIUM
IBM Spectrum Protect 7.1-8.1 - Denial of Service via TCP/IP Socket Leakage
CVSS 5.3
CVE-2018-15443 MEDIUM
Cisco Firepower System Software TCP Retransmission Handling Rule Bypass
CVSS 5.8
CVE-2018-15437 MEDIUM
Cisco Immunet & AMP for Endpoints - Resource Consumption in System Scanning
CVSS 5.5
CVE-2018-16845 MEDIUM
nginx <1.15.6, 1.14.1 - Memory Corruption
CVSS 6.1
CVE-2018-16844 HIGH
nginx < 1.14.1 - Uncontrolled Resource Consumption via HTTP/2 Implementation
CVSS 7.5
CVE-2018-16843 HIGH
nginx <1.15.6, 1.14.1 - Memory Corruption
CVSS 7.5
CVE-2018-16472 HIGH
cached-path-relative <=1.0.1 - Prototype Pollution via Input Validation Bypass
CVSS 7.5
CVE-2018-3935 HIGH
Yi Home Camera 27US 1.8.7.0D - Denial of Service via UDP Packet Memory Allocation
CVSS 7.5
CVE-2018-14660 MEDIUM
glusterfs 3.1.0-3.1.2 - Authenticated Denial of Service via GF_META_LOCK_KEY xattr
CVSS 6.5
CVE-2018-14659 MEDIUM
Gluster File System < 3.1.2 - Authenticated Denial of Service via GF_XATTR_IOSTATS_DUMP_KEY Attribute
CVSS 6.5
CVE-2018-15325 MEDIUM
BIG-IP 13.0.0-13.1.1.1 - Authenticated Memory Leak via iControl and TMSH Command Execution
CVSS 4.3
CVE-2018-18854 HIGH
Lightbend Spray spray-json < 1.3.4 - Denial of Service via Algorithmic Complexity in JSON Parsing
CVSS 7.5
CVE-2018-18853 HIGH
Lightbend Spray spray-json < 1.3.4 - Denial of Service via Algorithmic Complexity in Decimal Digit Parsing
CVSS 7.5
CVE-2018-16469 HIGH
merge < 1.2.1 - Denial of Service via Prototype Pollution
CVSS 7.5
Details
Vulnerabilities 3,152
Exploit Likelihood High