CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2017-9104 CRITICAL
adns < 1.5.2 - Denial of Service via Compression Pointer Loop
CVSS 9.8
CVE-2017-12806 HIGH
ImageMagick 7.0.6-6 - Denial of Service via Memory Exhaustion in format8BIM
CVSS 7.5
CVE-2017-12805 HIGH
ImageMagick 7.0.6-6 - Denial of Service via ReadTIFFImage Memory Exhaustion
CVSS 7.5
CVE-2017-12804 MEDIUM
ImageWorsener 1.3.2 - Denial of Service via Crafted File
CVSS 6.5
CVE-2017-0938 HIGH
airMAX <8.3.2, airMAX <6.0.7, EdgeMAX <1.9.7 - DoS
CVSS 7.5
CVE-2017-3144 HIGH
ISC DHCP 4.1.0-4.1-ESV-R15 4.2.0-4.2.8 4.3.0-4.3.6 - Uncontrolled Resource Consumption via OMAPI Connection Cleanup
CVSS 7.5
CVE-2017-3140 LOW
BIND 9.9.10, 9.10.5, 9.11.0-9.11.1 - Denial of Service via Response Policy Zone Rule Processing
CVSS 3.7
CVE-2017-9732 HIGH
kerberised_netcat < 1.11-1 - Unauthenticated Denial of Service via read_packet Memory Exhaustion
CVSS 7.5
CVE-2017-18299 MEDIUM
Qualcomm Snapdragon Firmware - Denial of Service via Translation Table Consolidation Logic
CVSS 5.5
CVE-2017-1794 HIGH
IBM Tivoli Monitoring 6.2.3-6.2.3.5 and 6.3.0-6.3.0.7 - Denial of Service via Unconstrained Memory Growth
CVSS 7.5
CVE-2017-5693 HIGH
Intel Puma Firmware - Denial of Service via Crafted Network Traffic
CVSS 7.5
CVE-2017-15119 MEDIUM
QEMU < 2.11.0 - Denial of Service via Large NBD Option Requests
CVSS 5.8
CVE-2017-6779 HIGH
Cisco Voice Operating System - Unauthenticated Denial of Service via Log File Disk Consumption
CVSS 7.5
CVE-2017-16138 HIGH
mime module <1.4.1, 2.0.1, 2.0.2 - DoS
CVSS 7.5
CVE-2017-16137 MEDIUM
debug < 2.6.9 - Regular Expression Denial of Service via o Formatter
CVSS 5.3
CVE-2017-16136 HIGH
expressjs method-override < 2.3.10 - Denial of Service via X-HTTP-Method-Override Header
CVSS 7.5
CVE-2017-16129 MEDIUM
superagent < 3.7.0 - Denial of Service via ZIP Bomb Response
CVSS 5.9
CVE-2017-16119 HIGH
fresh < 0.5.2 - Denial of Service via Regular Expression
CVSS 7.5
CVE-2017-16118 HIGH
forwarded < 0.1.2 - Denial of Service via Regular Expression
CVSS 7.5
CVE-2017-16117 HIGH
slug < 0.9.1 - Regular Expression Denial of Service via Crafted Unicode Input
CVSS 7.5
CVE-2017-16116 HIGH
string < 0.2.1 - Denial of Service via Regular Expression in underscore or unescapeHTML
CVSS 7.5
CVE-2017-16115 HIGH
timespan - Regular Expression Denial of Service via Untrusted User Input
CVSS 7.5
CVE-2017-16114 HIGH
marked < 0.3.9 - Regular Expression Denial of Service
CVSS 7.5
CVE-2017-16113 HIGH
parsejson < 0.0.3 - Regular Expression Denial of Service via Untrusted Input
CVSS 7.5
CVE-2017-16111 HIGH
content < 3.0.5, npm/content < 3.0.7 - Denial of Service via Crafted Content-Type or Content-Disposition Header
CVSS 7.5
Details
Vulnerabilities 3,152
Exploit Likelihood High