CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2014-3648 HIGH
JBoss AeroGear - Uncontrolled Resource Consumption via SimplePush Server DeviceToken
CVSS 7.5
CVE-2014-8937 HIGH
Lexiglot < 2014-11-20 - Denial of Service via SVN Update Operation
CVSS 7.5
CVE-2014-3447 HIGH
BSS Continuity CMS 4.2.22640.0 - Remote Denial of Service
CVSS 7.5
CVE-2014-3211 HIGH
Publify < 8.0.1 - Denial of Service
CVSS 7.5
CVE-2014-0212 HIGH
Apache Qpid C++ - Denial of Service via ACL Policy File Descriptor Exhaustion
CVSS 7.5
CVE-2014-10064 HIGH
QS < 1.0.0 - Denial of Service
CVSS 7.5
CVE-2014-2885 HIGH
TrueCrypt 7.1a - Integer Overflow in EncryptedIoQueue.c and Ntdriver.c
CVSS 7.1
CVE-2014-3651 HIGH
Keycloak < 1.0.3 - Denial of Service via Large QR Code Size Parameter
CVSS 7.5
CVE-2014-7813 MEDIUM
Red Hat CloudForms 3.0 Management Engine - Authenticated Denial of Service via Symbol Table Exhaustion
CVSS 6.5
CVE-2014-9697 HIGH
Huawei USG9560/9520/9580 <V300R001C01SPC300 - Memory Corruption
CVSS 7.5
CVE-2014-9849 HIGH
ImageMagick - Denial of Service
CVSS 7.5
CVE-2014-9842 HIGH
ImageMagick 6.8.9.9 - Memory Corruption
CVSS 7.5
CVE-2014-3672 MEDIUM
libvirt < 1.3.0 - Denial of Service via Guest OS Stdout/Stderr Write
CVSS 6.5
CVE-2014-5418
GE Multilink ML800/1200/1600/2400 < 4.2.1 and ML810/3000/3100 < 5.2.0 - Denial of Service via Crafted Packets
CVE-2014-8124
OpenStack Horizon 2014.1-2014.1.2 and 2014.2 - Denial of Service via Login Page Session Handling
CVE-2014-7255 HIGH
Internet Initiative Japan Inc. SEIL Series - DoS
CVSS 7.5
CVE-2014-3407
Cisco Adaptive Security Appliance Software < 9.3(2) - Denial of Service via SSL VPN HTTP Packet Handling
CVE-2014-8559 MEDIUM
Linux Kernel < 3.17.2 - Denial of Service via d_walk Deadlock
CVSS 5.5
CVE-2014-3690 MEDIUM
Linux Kernel < 3.17.2 - Denial of Service via KVM CR4 Register Handling
CVSS 5.5
CVE-2014-3687 HIGH
Linux Kernel 2.6.27-3.17.2 - Denial of Service via Duplicate ASCONF Chunks
CVSS 7.5
CVE-2014-7970 MEDIUM
Linux Kernel < 3.17 - Denial of Service via pivot_root Chroot Directory Handling
CVSS 5.5
CVE-2014-3328
Cisco Unified Presence Server - Denial of Service via TCP SYN Flood
CVE-2014-0118
Apache HTTP Server < 2.4.10 - Denial of Service via Request Body Decompression
CVE-2014-2343
Triangle MicroWorks SCADA Data Gateway <3.00.0635 - DoS
CVE-2014-2342
Triangle MicroWorks SCADA Data Gateway <3.00.0635 - DoS
Details
Vulnerabilities 3,152
Exploit Likelihood High