CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2017-12293 HIGH
Cisco WebEx Meetings Server - Unauthenticated Denial of Service via Connection Exhaustion
CVSS 8.6
CVE-2017-15596 MEDIUM
Xen 4.4.x-4.9.x - Denial of Service via Lock Mishandling on ARM
CVSS 6.0
CVE-2017-15595 HIGH
Xen < 4.9.0 - Denial of Service via Page-Table Stacking
CVSS 8.8
CVE-2017-15298 MEDIUM
Git < 2.14.2 - Denial of Service via Crafted Repository
CVSS 5.5
CVE-2017-10621 MEDIUM
Junos OS Multiple Versions - Unauthenticated DoS via Telnetd
CVSS 5.3
CVE-2017-10614 MEDIUM
Junos OS Multiple Versions - Denial of Service via Telnetd Memory/CPU Consumption
CVSS 5.3
CVE-2017-10613 MEDIUM
Juniper Junos OS - Denial of Service via Loopback Filter Action Command
CVSS 5.5
CVE-2017-10608 HIGH
Juniper Junos OS < 12.1X46-D55, 12.1X47-D45, 12.3X48-D35, 15.1X49-D60 DoS via Sun/MS-RPC ALG IPv6
CVSS 7.5
CVE-2017-15193 HIGH
Wireshark 2.4.0-2.4.1 and 2.2.0-2.2.9 - Denial of Service in MBIM Dissector
CVSS 7.5
CVE-2017-5637 HIGH
Apache ZooKeeper 3.4.0-3.4.9 and 3.5.0-3.5.2 - Unauthenticated Denial of Service via wchp/wchc Commands
CVSS 7.5
CVE-2017-14086 HIGH
Trend Micro OfficeScan 11.0 - Use After Free
CVSS 7.5
CVE-2017-15010 HIGH
tough-cookie < 2.3.3 - Uncontrolled Resource Consumption via ReDoS
CVSS 7.5
CVE-2017-14988 MEDIUM
OpenEXR 2.2.0 - Denial of Service via Crafted File in ImfOpenInputFile
CVSS 5.5
CVE-2017-8247 HIGH
Android < 8.0 - Uncontrolled Resource Consumption via Multiple Device Open Operations
CVSS 7.8
CVE-2017-14616 HIGH
WatchGuard Fireware < 11.12.4 - Denial of Service via XML-RPC Empty Member Element
CVSS 7.5
CVE-2017-14342 MEDIUM
ImageMagick 7.0.6-6 - Memory Corruption
CVSS 6.5
CVE-2017-14341 MEDIUM
ImageMagick 7.0.6-6 - Uncontrolled Resource Consumption via Crafted WPG Image
CVSS 6.5
CVE-2017-14223 MEDIUM
FFmpeg - Denial of Service via ASF File with Large 'ict' Field
CVSS 6.5
CVE-2017-14158 HIGH
Scrapy - Denial of Service via Large File Memory Consumption
CVSS 7.5
CVE-2017-14108 MEDIUM
GNOME gedit < 3.22.1 - Denial of Service via File with Leading Null Bytes
CVSS 5.5
CVE-2017-14137 HIGH
ImageMagick 7.0.6-5 - Memory Corruption
CVSS 7.5
CVE-2017-12077 MEDIUM
Synology Router Manager <1.1.4-6509 - DoS
CVSS 4.9
CVE-2017-12076 MEDIUM
Synology DiskStation Manager < 6.1.1-15088 - Authenticated Denial of Service via Port Forwarding Rules
CVSS 4.9
CVE-2017-8264 HIGH
Google Android - Denial of Service
CVSS 7.8
CVE-2017-12140 MEDIUM
ImageMagick 7.0.6-1 - Memory Corruption
CVSS 6.5
Details
Vulnerabilities 3,152
Exploit Likelihood High