CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
3,738 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 3 of 75
- CVE-2013-7470MEDIUMCVSS 5.9EG 5.92019-04-23
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerabili…
- CVE-2014-0118MEDIUMCVSS v2 4.3EG 4.32014-07-20
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via …
- CVE-2014-0212HIGHCVSS 7.5EG 7.52019-12-13
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
- CVE-2014-10064HIGHCVSS 7.5EG 7.52018-05-31
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to …
- CVE-2014-1500MEDIUMCVSS v2 5.0EG 5.02014-03-19
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
- CVE-2014-2342MEDIUMCVSS v2 5.0EG 5.02014-05-30
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet.
- CVE-2014-2343LOWCVSS v2 2.1EG 2.12014-05-30
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line.
- CVE-2014-2885HIGHCVSS 7.1EG 7.12018-03-19
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of ser…
- CVE-2014-3122MEDIUMCVSS v2 4.9EG 4.92014-05-11
The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage patte…
- CVE-2014-3211HIGHCVSS 7.5EG 7.52020-01-09
Publify before 8.0.1 is vulnerable to a Denial of Service attack
- CVE-2014-3328MEDIUMCVSS v2 5.0EG 5.02014-07-26
The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of service via a TCP SYN flood, aka Bug ID CSCun34125.
- CVE-2014-3407MEDIUMCVSS v2 5.0EG 5.02014-11-28
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory con…
- CVE-2014-3447HIGHCVSS 7.5EG 7.52020-01-09
BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability
- CVE-2014-3648HIGHCVSS 7.5EG 7.52022-07-01
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generat…
- CVE-2014-3651HIGHCVSS 7.5EG 7.52017-12-29
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.
- CVE-2014-3672MEDIUMCVSS 6.5EG 6.52016-05-25
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
- CVE-2014-3687HIGHCVSS 7.5EG 7.52014-11-10
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorr…
- CVE-2014-3690MEDIUMCVSS 5.5EG 5.52014-11-10
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary proces…
- CVE-2014-5418HIGHCVSS v2 7.8EG 7.82015-01-17
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumpt…
- CVE-2014-7255HIGHCVSS 7.5EG 7.52014-12-05
Internet Initiative Japan Inc. SEIL Series routers SEIL/X1 2.50 through 4.62, SEIL/X2 2.50 through 4.62, SEIL/B1 2.50 through 4.62, and SEIL/x86 Fuji 1.70 through 3.22 allow remote attackers to cause a denial of service (CPU and traffic co…
- CVE-2014-7813MEDIUMCVSS 6.5EG 6.52017-10-18
Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors involving calls to the .to_sym rails function and lack of garbage collection of inserted symbol…
- CVE-2014-7970MEDIUMCVSS 5.5EG 5.52014-10-13
The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) v…
- CVE-2014-8124MEDIUMCVSS v2 5.0EG 5.02014-12-12
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number …
- CVE-2014-8559MEDIUMCVSS 5.5EG 5.52014-11-10
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
- CVE-2014-8937HIGHCVSS 7.5EG 7.52020-06-01
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.
- CVE-2014-9697HIGHCVSS 7.5EG 7.52017-10-17
Huawei USG9560/9520/9580 before V300R001C01SPC300 allows remote attackers to cause a memory leak or denial of service (memory exhaustion, reboot and MPU switchover) via a crafted website.
- CVE-2014-9842HIGHCVSS 7.5EG 7.52017-03-20
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
- CVE-2014-9849HIGHCVSS 7.5EG 7.52017-03-20
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
- CVE-2015-1417HIGHCVSS 7.5EG 7.52017-07-25
The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET enabled and at leas…
- CVE-2015-1779HIGHCVSS 8.6EG 8.62016-01-12
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
- CVE-2015-1916HIGHCVSS 7.5EG 7.52015-07-02
Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and the Secure Socket Extension provider.
- CVE-2015-2312HIGHCVSS 7.5EG 7.52017-08-09
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a large number of elements.
- CVE-2015-2313HIGHCVSS 7.5EG 7.52017-08-09
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption) via a crafted small message, which trig…
- CVE-2015-3248MEDIUMCVSS 4.7EG 4.72017-09-26
openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions for /var/lib/openhpi directory, which allows local users, when quotas are not properly setup, to fill the filesystem hosting /var/lib and cause a denial of service…
- CVE-2015-4411HIGHCVSS 7.5EG 7.52020-02-20
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomp…
- CVE-2015-4412CRITICALCVSS 9.8EG 9.82018-02-05
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.
- CVE-2015-5333HIGHCVSS 7.5EG 7.52020-01-23
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.
- CVE-2015-5600HIGHCVSS 8.1EG 8.12015-08-03
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct bru…
- CVE-2015-5695MEDIUMCVSS 6.5EG 6.52017-08-31
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denia…
- CVE-2015-7384HIGHCVSS 7.5EG 7.52017-10-10
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
- CVE-2015-7978HIGHCVSS 7.5EG 7.52017-01-30
NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via an ntpdc relist command, which triggers recursive traversal of the restriction list.
- CVE-2015-9239HIGHCVSS 7.5EG 7.52018-05-31
ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
- CVE-2015-9241HIGHCVSS 7.5EG 7.52018-05-29
Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 error back to the sender, hapi node module before 11.1.3 will continue to hold th…
- CVE-2015-9242HIGHCVSS 7.5EG 7.52018-05-29
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via…
- CVE-2015-9253MEDIUMCVSS 6.5EG 6.52018-02-19
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec…
- CVE-2015-9548HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.
- CVE-2016-0747MEDIUMCVSS 5.3EG 5.32016-02-15
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name res…
- CVE-2016-10047MEDIUMCVSS 5.5EG 5.52017-03-23
Memory leak in the NewXMLTree function in magick/xml-tree.c in ImageMagick before 6.9.4-7 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML file.
- CVE-2016-10058MEDIUMCVSS 5.5EG 5.52017-03-23
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick before 6.9.6-3 allows remote attackers to cause a denial of service (memory consumption) via a crafted image file.
- CVE-2016-10520HIGHCVSS 7.5EG 7.52018-05-31
jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →