CWE-399
447 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-399page 6 of 9
- CVE-2016-7972HIGHCVSS 7.5EG 7.52017-03-03
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
- CVE-2016-8463MEDIUMCVSS 5.5EG 5.52017-01-12
A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of serv…
- CVE-2016-8579MEDIUMCVSS 4.0EG 4.02016-10-28
docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.
- CVE-2016-8650MEDIUMCVSS 5.5EG 5.52016-11-28
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key …
- CVE-2016-8740HIGHCVSS 7.5EG 8.82016-12-05
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumpt…
- CVE-2016-8781MEDIUMCVSS 6.5EG 6.52017-04-02
Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with software V500R001C20, Secospace USG6600 with software V500R001C20 and V500R001C20SPC200PWE allow remote attackers with specific permission …
- CVE-2016-8782MEDIUMCVSS 5.3EG 5.32018-03-09
Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices repeatedly. D…
- CVE-2016-8784MEDIUMCVSS 4.3EG 4.32018-03-09
Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the val…
- CVE-2016-8797HIGHCVSS 7.5EG 7.52017-04-02
Huawei AR3200 with software V200R007C00, V200R005C32, V200R005C20; S12700 with software V200R008C00, V200R007C00; S5300 with software V200R008C00, V200R007C00, V200R006C00; S5700 with software V200R008C00, V200R007C00, V200R006C00; S6300 w…
- CVE-2016-8826MEDIUMCVSS 5.5EG 5.52016-12-16
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) where a user can cause a GPU interrupt storm, leading to a denial of service.
- CVE-2016-8858HIGHCVSS 7.5EG 7.52016-12-09
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH ups…
- CVE-2016-8883MEDIUMCVSS 5.5EG 5.52017-01-13
The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
- CVE-2016-8919HIGHCVSS 7.5EG 7.52017-02-01
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
- CVE-2016-9191MEDIUMCVSS 5.5EG 5.52016-11-28
The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a c…
- CVE-2016-9194MEDIUMCVSS 6.5EG 6.52017-04-06
A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vuln…
- CVE-2016-9195MEDIUMCVSS 5.3EG 5.32017-04-07
A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by disconnecting a single co…
- CVE-2016-9198HIGHCVSS 7.5EG 7.52016-12-14
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected…
- CVE-2016-9205HIGHCVSS 7.5EG 7.52016-12-14
A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. …
- CVE-2016-9216MEDIUMCVSS 5.3EG 5.32017-01-26
An IKE Packet Parsing Denial of Service Vulnerability in the ipsecmgr process of Cisco ASR 5000 Software could allow an unauthenticated, remote attacker to cause the ipsecmgr process to reload. More Information: CSCuy06917 CSCuy45036 CSCuy…
- CVE-2016-9220MEDIUMCVSS 4.3EG 4.32017-01-26
A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause the connection table to be full of invalid con…
- CVE-2016-9221MEDIUMCVSS 4.3EG 4.32017-01-26
A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affe…
- CVE-2016-9225HIGHCVSS 8.6EG 8.62017-02-01
A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further tr…
- CVE-2016-9312HIGHCVSS 7.5EG 7.52017-01-13
ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.
- CVE-2016-9332HIGHCVSS 7.5EG 7.52017-02-13
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide unexpected values and cause the program to crash or excessive consumption of resource…
- CVE-2016-9354MEDIUMCVSS 5.5EG 5.52017-02-13
An issue was discovered in Moxa DACenter Versions 1.4 and older. A specially crafted project file may cause the program to crash because of Uncontrolled Resource Consumption.
- CVE-2016-9372MEDIUMCVSS 5.9EG 5.92016-11-17
In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in plugins/profinet/packet-pn-rtc-one.c by rejecting input with too many I/O objects.
- CVE-2016-9374MEDIUMCVSS 5.9EG 5.92016-11-17
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length var…
- CVE-2016-9375MEDIUMCVSS 5.9EG 5.92016-11-17
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was su…
- CVE-2016-9376MEDIUMCVSS 5.9EG 5.92016-11-17
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflow_v5.c by ensuring that certain …
- CVE-2016-9561MEDIUMCVSS 5.5EG 5.52016-12-23
The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.
- CVE-2016-9592MEDIUMCVSS 4.3EG 4.32018-04-16
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30 seconds for each vo…
- CVE-2016-9633MEDIUMCVSS 6.5EG 6.52016-12-12
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (infinite loop and resource consumption) via a crafted HTML page.
- CVE-2016-9740HIGHCVSS 7.5EG 7.52017-03-07
IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556.
- CVE-2016-9814CRITICALCVSS 9.1EG 9.12017-02-17
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly caus…
- CVE-2016-9954HIGHCVSS 7.5EG 7.52017-04-21
The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern.
- CVE-2017-11580MEDIUMCVSS 6.5EG 6.52019-07-02
Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTT…
- CVE-2017-12211MEDIUMCVSS 5.3EG 5.32017-09-07
A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device. The vulnerability is due to …
- CVE-2017-12219HIGHCVSS 7.5EG 7.52017-09-21
A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of s…
- CVE-2017-12222MEDIUMCVSS 6.5EG 6.52017-09-29
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition. The vulnerability is due to insufficie…
- CVE-2017-12231CRITICALCVSS 7.5EG 9.0⚠ KEV2017-09-29
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The…
- CVE-2017-12232CRITICALCVSS 6.5EG 9.0⚠ KEV2017-09-29
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to rel…
- CVE-2017-12237CRITICALCVSS 7.5EG 9.0⚠ KEV2017-09-29
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a …
- CVE-2017-12238CRITICALCVSS 6.5EG 9.0⚠ KEV2017-09-29
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line ca…
- CVE-2017-12245HIGHCVSS 8.6EG 8.62017-10-05
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consump…
- CVE-2017-12246HIGHCVSS 8.6EG 8.62017-10-05
A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in…
- CVE-2017-12250MEDIUMCVSS 5.3EG 5.32017-09-21
A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial o…
- CVE-2017-12256MEDIUMCVSS 6.5EG 6.52017-10-05
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device. The vulnerability i…
- CVE-2017-12287MEDIUMCVSS 4.3EG 4.32017-10-19
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process …
- CVE-2017-12311MEDIUMCVSS 5.8EG 5.82017-11-16
A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server media process to restart unexpectedly when it receives an illegal H.264 frame. The vulner…
- CVE-2017-12318HIGHCVSS 7.5EG 7.52017-11-16
A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting i…
Map vulnerabilities like CWE-399 to your infrastructure
EchelonGraph correlates every CVE — across CWE-399 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →