CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2018-11828 HIGH
Qualcomm Snapdragon Mobile - Infinite Loop via Constant ADC Values
CVSS 7.5
CVE-2018-0441 HIGH
Cisco IOS Access Points < 8.3.140.0 - Unauthenticated Denial of Service via 802.11r Fast Transition Reassociation Events
CVSS 7.4
CVE-2018-0381 MEDIUM
Cisco Aironet Series Access Points - Authenticated Denial of Service via SSID Transition Deadlock
CVSS 6.8
CVE-2018-17898 HIGH
Yokogawa STARDOM Controllers - Memory Corruption
CVSS 7.5
CVE-2018-0063 MEDIUM
Junos OS 17.3R3 - Denial of Service via ARP Request Flood to Management Interface
CVSS 6.5
CVE-2018-0061 MEDIUM
Junos OS - Unauthenticated Denial of Service via Telnetd Service
CVSS 5.3
CVE-2018-0054 MEDIUM
Juniper Junos OS on QFX5000 Series and EX4600 - Denial of Service via Ethernet Pause Frames or ARP Packet Storm
CVSS 6.5
CVE-2018-0048 HIGH
Junos OS 17.2-18.1 - Unauthenticated Denial of Service via RPD Memory Exhaustion
CVSS 7.5
CVE-2018-13805 HIGH
Siemens Simatic ET 200sp Firmware < 2.5 - Denial of Service
CVSS 7.5
CVE-2018-17977 MEDIUM
Linux Kernel 4.14.67 - Denial of Service via XFRM Netlink Message Interaction
CVSS 4.4
CVE-2018-15399 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via TCP Syslog Header Manipulation
CVSS 6.8
CVE-2018-15396 MEDIUM
Cisco Unity Connection - Authenticated Denial of Service via Bulk Administration Tool File Write
CVSS 6.8
CVE-2018-15383 HIGH
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via DMA Memory Exhaustion
CVSS 7.5
CVE-2018-15377 HIGH
Cisco IOS Software/Cisco IOS XE Software - Memory Leak
CVSS 8.6
CVE-2018-0471 HIGH
Cisco IOS XE 16.6.1-16.6.2 - Unauthenticated Denial of Service via CDP Packet Processing
CVSS 7.4
CVE-2018-17985 MEDIUM
GNU Binutils - Denial of Service via Recursive Type Demangling in cplus_demangle_type
CVSS 5.5
CVE-2018-14648 HIGH
389 Directory Server < 1.4.0.17 - Unauthenticated Denial of Service via Crafted Search Query
CVSS 7.5
CVE-2018-17581 MEDIUM
Exiv2 0.26 - Denial of Service via Recursive CiffDirectory::readDirectory()
CVSS 6.5
CVE-2018-8854 HIGH
Philips e-Alert Unit <R2.1 - Info Disclosure
CVSS 7.5
CVE-2018-17281 HIGH
Asterisk 13.0.0-13.23.0, 14.0.0-14.7.7, 15.0.0-15.6.0 DoS via WebSocket Upgrade
CVSS 7.5
CVE-2018-14827 HIGH
Rockwell Automation RSLinx Classic <4.00.01 - DoS
CVSS 7.5
CVE-2018-14638 HIGH
389 Directory Server < 1.3.8.4 - Denial of Service via Persistent Search Connection Termination
CVSS 7.5
CVE-2018-16949 HIGH
OpenAFS < 1.6.23 and 1.8.x < 1.8.2 - Unauthenticated Denial of Service via Unbounded RPC Input
CVSS 7.5
CVE-2018-1114 MEDIUM
Undertow < 1.4.25.Final - File Descriptor Leak via URLResource.getLastModified()
CVSS 6.5
CVE-2018-10935 MEDIUM
389 Directory Server 1.3.0.0-1.3.8.7 - Denial of Service via LDAP Server-Side Sort
CVSS 6.5
Details
Vulnerabilities 3,152
Exploit Likelihood High