CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2012-0049 MEDIUM
OpenTTD < 1.1.5 - Denial of Service via Slow Read Attack
CVSS 4.3
CVE-2012-6638
Linux Kernel < 3.0.38 - Denial of Service via SYN+FIN TCP Packet Flood
CVE-2012-0876
libexpat < 2.1.0 - Denial of Service via Hash Collision in XML Parser
CVE-2012-0260 MEDIUM
ImageMagick < 6.7.6-3 - Denial of Service via Crafted JPEG Restart Markers
CVSS 6.5
CVE-2012-0879 MEDIUM
Linux Kernel < 2.6.33 - Denial of Service via CLONE_IO Feature
CVSS 5.5
CVE-2012-0058 MEDIUM
Linux Kernel < 3.2.2 - Denial of Service via Incorrect iocb Management
CVSS 5.5
CVE-2012-0382 HIGH
Cisco IOS 12.0-12.4, 15.0-15.2 & IOS XE 2.1.x-2.6.x, 3.1.xS-3.4.xS <3.4.1S, 3.1.xSG-3.2.xSG <3.2.2SG DoS via MSDP IGMP
CVSS 7.5
CVE-2012-0024
MaraDNS < 1.3.07.12 and 1.4.x < 1.4.08 - Denial of Service via DNS Query Hash Collisions
CVE-2011-3336 HIGH
PHP 5.3.0-5.3.9 - Denial of Service via Stack Exhaustion in regcomp
CVSS 7.5
CVE-2011-1474 MEDIUM
Linux Kernel - Denial of Service via MAP_GROWSDOWN mmap Bounds Check
CVSS 5.5
CVE-2011-4082 HIGH
phpldapadmin < 0.9.8 - Denial of Service via Accept-Language Header
CVSS 7.5
CVE-2011-1459 MEDIUM
Blink < M11 - Denial of Service via WebPluginContainerImpl Event Handling
CVSS 6.5
CVE-2011-2491
Linux Kernel < 3.0 - Denial of Service via NLM LOCK_UN flock System Call
CVE-2011-2918 MEDIUM
Linux Kernel < 3.1 - Denial of Service via Performance Events Subsystem
CVSS 5.5
CVE-2011-2906 MEDIUM
Linux Kernel < 3.1 - Denial of Service via pmcraid_ioctl_passthrough Negative Size Value
CVSS 5.5
CVE-2011-3954
Google Chrome < 17.0.963.46 - Denial of Service via Database Resource Exhaustion
CVE-2011-5056
MaraDNS < 2.0.04 - Denial of Service via DNS Hash Collision
CVE-2011-4838
JRuby < 1.6.5.1 - Denial of Service via Hash Collision
CVE-2011-1640 HIGH
Cisco IOS 12.2 < 12.2(33)SXJ1 - Denial of Service via LLDP Management Address TLV
CVSS 7.5
CVE-2011-2189 HIGH
Linux Kernel < 2.6.32 - Denial of Service via Network Namespace Creation
CVSS 7.5
CVE-2011-3348
Apache HTTP Server 2.2.12-2.2.20 - Denial of Service via mod_proxy_ajp Malformed HTTP Request
CVE-2011-3192
Apache HTTP Server 1.3.x 2.0.35-2.0.64 2.2.0-2.2.19 - Denial of Service via Range Header Overlap
CVE-2011-2689
Linux Kernel < 3.0 - Denial of Service via GFS2 Chunk Allocation
CVE-2011-1083
Linux Kernel < 2.6.37.2 - Denial of Service via epoll File Descriptor Tree Traversal
CVE-2011-1082
Linux Kernel < 2.6.38 - Denial of Service via epoll File Descriptor Chaining
Details
Vulnerabilities 3,152
Exploit Likelihood High