CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,152 vulnerabilities with CWE-400
CVE-2017-9104
CRITICAL
adns < 1.5.2 - Denial of Service via Compression Pointer Loop
CVSS 9.8
CVE-2017-12806
HIGH
ImageMagick 7.0.6-6 - Denial of Service via Memory Exhaustion in format8BIM
CVSS 7.5
CVE-2017-12805
HIGH
ImageMagick 7.0.6-6 - Denial of Service via ReadTIFFImage Memory Exhaustion
CVSS 7.5
CVE-2017-12804
MEDIUM
ImageWorsener 1.3.2 - Denial of Service via Crafted File
CVSS 6.5
CVE-2017-0938
HIGH
airMAX <8.3.2, airMAX <6.0.7, EdgeMAX <1.9.7 - DoS
CVSS 7.5
CVE-2017-3144
HIGH
ISC DHCP 4.1.0-4.1-ESV-R15 4.2.0-4.2.8 4.3.0-4.3.6 - Uncontrolled Resource Consumption via OMAPI Connection Cleanup
CVSS 7.5
CVE-2017-3140
LOW
BIND 9.9.10, 9.10.5, 9.11.0-9.11.1 - Denial of Service via Response Policy Zone Rule Processing
CVSS 3.7
CVE-2017-9732
HIGH
kerberised_netcat < 1.11-1 - Unauthenticated Denial of Service via read_packet Memory Exhaustion
CVSS 7.5
CVE-2017-18299
MEDIUM
Qualcomm Snapdragon Firmware - Denial of Service via Translation Table Consolidation Logic
CVSS 5.5
CVE-2017-1794
HIGH
IBM Tivoli Monitoring 6.2.3-6.2.3.5 and 6.3.0-6.3.0.7 - Denial of Service via Unconstrained Memory Growth
CVSS 7.5
CVE-2017-5693
HIGH
Intel Puma Firmware - Denial of Service via Crafted Network Traffic
CVSS 7.5
CVE-2017-15119
MEDIUM
QEMU < 2.11.0 - Denial of Service via Large NBD Option Requests
CVSS 5.8
CVE-2017-6779
HIGH
Cisco Voice Operating System - Unauthenticated Denial of Service via Log File Disk Consumption
CVSS 7.5
CVE-2017-16138
HIGH
mime module <1.4.1, 2.0.1, 2.0.2 - DoS
CVSS 7.5
CVE-2017-16137
MEDIUM
debug < 2.6.9 - Regular Expression Denial of Service via o Formatter
CVSS 5.3
CVE-2017-16136
HIGH
expressjs method-override < 2.3.10 - Denial of Service via X-HTTP-Method-Override Header
CVSS 7.5
CVE-2017-16129
MEDIUM
superagent < 3.7.0 - Denial of Service via ZIP Bomb Response
CVSS 5.9
CVE-2017-16119
HIGH
fresh < 0.5.2 - Denial of Service via Regular Expression
CVSS 7.5
CVE-2017-16118
HIGH
forwarded < 0.1.2 - Denial of Service via Regular Expression
CVSS 7.5
CVE-2017-16117
HIGH
slug < 0.9.1 - Regular Expression Denial of Service via Crafted Unicode Input
CVSS 7.5
CVE-2017-16116
HIGH
string < 0.2.1 - Denial of Service via Regular Expression in underscore or unescapeHTML
CVSS 7.5
CVE-2017-16115
HIGH
timespan - Regular Expression Denial of Service via Untrusted User Input
CVSS 7.5
CVE-2017-16114
HIGH
marked < 0.3.9 - Regular Expression Denial of Service
CVSS 7.5
CVE-2017-16113
HIGH
parsejson < 0.0.3 - Regular Expression Denial of Service via Untrusted Input
CVSS 7.5
CVE-2017-16111
HIGH
content < 3.0.5, npm/content < 3.0.7 - Denial of Service via Crafted Content-Type or Content-Disposition Header
CVSS 7.5
Details
Vulnerabilities
3,152
Exploit Likelihood
High