CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,152 vulnerabilities with CWE-400
CVE-2020-1625 MEDIUM
Juniper Junos OS - Denial of Service via IRB Interface Flap Memory Leak
CVSS 6.5
CVE-2020-5347 MEDIUM
Dell EMC Isilon OneFS < 8.2.2 - Denial of Service via SmartConnect DNS Response Loop
CVSS 5.3
CVE-2020-5527 HIGH
Mitsubishi Electric MELSEC - DoS
CVSS 7.5
CVE-2020-10954 HIGH
GitLab < 12.9 - Denial of Service via Repository Archive Download
CVSS 7.5
CVE-2020-1950 MEDIUM
Apache Tika 1.0-1.23 - Uncontrolled Resource Consumption in PSDParser
CVSS 5.5
CVE-2020-8136 HIGH
fastify-multipart < 1.0.5 - Memory Corruption
CVSS 7.5
CVE-2020-0088 MEDIUM
Android 10 - Denial of Service via MPEG4Extractor Track Fragment Parsing
CVSS 6.5
CVE-2020-9464 HIGH
BECKHOFF Ethernet TCP/IP Bus Coupler BK9000 - Denial of Service
CVSS 7.5
CVE-2020-7212 HIGH
urllib3 1.25.2-1.25.7 - Denial of Service via Inefficient Percent-Encoding Algorithm
CVSS 7.5
CVE-2020-6986 HIGH
Omron PLC CJ Series - Denial of Service via Ethernet Packet Flood
CVSS 7.5
CVE-2020-8661 HIGH
CNCF Envoy <1.13.0 - Memory Corruption
CVSS 7.5
CVE-2020-3190 MEDIUM
Cisco IOS XR < 6.4.3 - Unauthenticated Denial of Service via Malicious ICMP Error Messages
CVSS 5.8
CVE-2020-3181 MEDIUM
Cisco AsyncOS Software - Memory Corruption
CVSS 6.5
CVE-2020-3175 HIGH
Cisco NX-OS for MDS 9000 Series - Unauthenticated Denial of Service via Management Interface Traffic Flood
CVSS 8.6
CVE-2020-3168 HIGH
Cisco NX-OS - Unauthenticated Denial of Service via Secure Login Enhancements
CVSS 7.5
CVE-2020-9369 HIGH
Sympa 6.2.38-6.2.52 - Denial of Service via Malformed Parameter Requests
CVSS 7.5
CVE-2020-3132 MEDIUM
Cisco Email Security Appliance < 12.5.1-037 - Unauthenticated Denial of Service via Malicious Email with Shortened URLs
CVSS 5.9
CVE-2020-8992 MEDIUM
Linux Kernel < 5.5.3 - Denial of Service via Crafted Journal Size
CVSS 5.5
CVE-2020-3741 HIGH
Adobe Experience Manager <6.5-6.4 - DoS
CVSS 7.5
CVE-2020-1700 MEDIUM
Ceph - Authenticated Denial of Service via RGW Beast Front-End Disconnect Handling
CVSS 6.5
CVE-2020-8123 MEDIUM
Strapi < 3.0.0-beta.18.3 - Authenticated Denial of Service via Admin Console
CVSS 4.9
CVE-2020-5236 MEDIUM
Waitress 1.4.2 - Denial of Service via Invalid Header Character Processing
CVSS 5.7
CVE-2020-8492 MEDIUM
Python 2.7.0-2.7.17 - Regular Expression Denial of Service via urllib.request.AbstractBasicAuthHandler
CVSS 6.5
CVE-2020-3131 MEDIUM
Cisco Webex Teams client for Windows - DoS
CVSS 6.5
CVE-2020-1600 MEDIUM
Juniper Junos OS - Unauthenticated Denial of Service via SNMP Request
CVSS 6.5
Details
Vulnerabilities 3,152
Exploit Likelihood High