CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2020-13238 HIGH
Mitsubishi MELSEC iQ-R Series <33 - DoS
CVSS 7.5
CVE-2020-13849 HIGH
MQTT 3.1.1 - Denial of Service via Keep-Alive Timeout Manipulation
CVSS 7.5
CVE-2020-7661 HIGH
url-regex - Regular Expression Denial of Service via String.test
CVSS 7.5
CVE-2020-13815 HIGH
Foxit Reader and PhantomPDF < 9.7.1 - Denial of Service via Indirect Object Reference Loop
CVSS 7.5
CVE-2020-13809 HIGH
Foxit Reader and PhantomPDF < 9.7.2 - Uncontrolled Resource Consumption via Long Strings in Content Stream
CVSS 7.5
CVE-2020-11080 LOW
nghttp2 < 1.41.0 - Denial of Service via Large HTTP/2 SETTINGS Frame Payload
CVSS 3.7
CVE-2020-3203 HIGH
Cisco IOS XE - Unauthenticated Denial of Service via PKI Packet Processing
CVSS 8.6
CVE-2020-13623 HIGH
JerryScript 2.2.0 - Denial of Service via Proxy Operation
CVSS 7.5
CVE-2020-10995 HIGH
PowerDNS Recursor 4.1.0-4.3.0 - Uncontrolled Resource Consumption via Random Subdomains in NS Records
CVSS 7.5
CVE-2020-8616 HIGH
BIND >=9.0.0 <9.11.18 - Uncontrolled Resource Consumption via Referral Processing
CVSS 8.6
CVE-2020-12662 HIGH
Unbound < 1.10.1 - Denial of Service via NXNSAttack
CVSS 7.5
CVE-2020-12667 HIGH
Knot Resolver < 5.1.1 - Uncontrolled Resource Consumption via NXNSAttack
CVSS 7.5
CVE-2020-3334 HIGH
Cisco ASA >=9.10 <9.10.1.37 & FTD <6.6.0 - DoS via ARP Packet Processing
CVSS 7.4
CVE-2020-3306 HIGH
Cisco ASA & FTD - Unauthenticated DoS via DHCP Packet Processing
CVSS 7.5
CVE-2020-3305 HIGH
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via BGP Packet Processing
CVSS 7.5
CVE-2020-3303 HIGH
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated Denial of Service via IKEv1 Traffic
CVSS 7.5
CVE-2020-3255 HIGH
Cisco Firepower Threat Defense - DoS
CVSS 7.5
CVE-2020-3254 HIGH
Cisco ASA & FTD MGCP Packet Handling Unauthenticated DoS
CVSS 7.5
CVE-2020-3196 HIGH
Cisco ASA and Firepower Threat Defense - Unauthenticated Denial of Service via SSL/TLS Connection Exhaustion
CVSS 8.6
CVE-2020-3195 HIGH
Cisco ASA & FTD OSPF Packet Processing Unauthenticated DoS
CVSS 7.5
CVE-2020-3189 HIGH
Cisco Firepower Threat Defense - Memory Leak
CVSS 8.6
CVE-2020-9481 HIGH
Apache Traffic Server 6.0.0-6.2.3, 7.0.0-7.1.9, 8.0.0-8.0.6 - Resource Consumption via HTTP/2 Slow Read
CVSS 7.5
CVE-2020-1722 MEDIUM
freeipa 4.0.0-4.8.0 - Denial of Service via Long Password Hashing
CVSS 5.3
CVE-2020-7486 HIGH
Schneider Electric Triconex TCM 4351/4352 Firmware v10.4.x and v10.3.x - Denial of Service via High Network Load
CVSS 7.5
CVE-2020-3260 MEDIUM
Cisco Aironet Series Access Points - Unauthenticated Denial of Service via Client Packet Processing
CVSS 6.5
Details
Vulnerabilities 3,152
Exploit Likelihood High