CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
3,739 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 5 of 75
- CVE-2017-0938HIGHCVSS 7.5EG 7.52019-02-12
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.
- CVE-2017-1000064HIGHCVSS 7.5EG 7.52017-07-17
kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS
- CVE-2017-1000191HIGHCVSS 7.5EG 7.52017-11-17
Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.
- CVE-2017-1000357HIGHCVSS 7.5EG 7.52017-04-24
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: Open…
- CVE-2017-1000359MEDIUMCVSS 5.3EG 5.32017-04-24
Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.
- CVE-2017-1000373MEDIUMCVSS 6.5EG 6.52017-06-19
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amount…
- CVE-2017-1000378CRITICALCVSS 9.8EG 9.82017-06-19
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts…
- CVE-2017-1000476MEDIUMCVSS 6.5EG 6.52018-01-03
ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.
- CVE-2017-10608HIGHCVSS 7.5EG 7.52017-10-13
Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker …
- CVE-2017-10613MEDIUMCVSS 5.5EG 5.52017-10-13
A vulnerability in a specific loopback filter action command, processed in a specific logical order of operation, in a running configuration of Juniper Networks Junos OS, allows an attacker with CLI access and the ability to initiate remot…
- CVE-2017-10614HIGHCVSS 7.5EG 7.52017-10-13
A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory and/or CPU consumption denial of service attack. This issue was found during internal product security testing. Affected releases are Juniper…
- CVE-2017-10621MEDIUMCVSS 5.3EG 5.32017-10-13
A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attackers to cause a denial of service. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-…
- CVE-2017-10799MEDIUMCVSS 5.5EG 5.52017-07-03
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().
- CVE-2017-10800MEDIUMCVSS 5.5EG 5.52017-07-03
When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.
- CVE-2017-10922HIGHCVSS 7.5EG 7.52017-07-05
The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.
- CVE-2017-11140MEDIUMCVSS 5.5EG 5.52017-07-10
The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.
- CVE-2017-11142HIGHCVSS 7.5EG 7.52017-07-10
In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.
- CVE-2017-11521HIGHCVSS 7.5EG 7.52017-07-22
The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of service (memory consumption) by triggering many media connections.
- CVE-2017-11526MEDIUMCVSS 6.5EG 6.52017-07-23
The ReadOneMNGImage function in coders/png.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted file.
- CVE-2017-11527MEDIUMCVSS 6.5EG 6.52017-07-23
The ReadDPXImage function in coders/dpx.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
- CVE-2017-11530MEDIUMCVSS 6.5EG 6.52017-07-23
The ReadEPTImage function in coders/ept.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
- CVE-2017-12076MEDIUMCVSS 4.9EG 4.92017-08-28
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of ser…
- CVE-2017-12077MEDIUMCVSS 4.9EG 4.92017-08-28
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of s…
- CVE-2017-12090HIGHCVSS 7.7EG 7.72018-04-05
An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted snmp-set request, when sent without associated firmware flas…
- CVE-2017-12093HIGHCVSS 5.3EG 7.52018-04-05
An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before. A specially crafted stream of packets can cause a flood of the se…
- CVE-2017-12140MEDIUMCVSS 6.5EG 6.52017-08-02
The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file.
- CVE-2017-12174HIGHCVSS 7.5EG 7.52018-03-07
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full …
- CVE-2017-12190MEDIUMCVSS 6.5EG 6.52017-11-22
The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector has small consecutive buffers belonging to the same page. The bio_add_pc_page function merg…
- CVE-2017-12237CRITICALCVSS 7.5EG 9.0⚠ KEV2017-09-29
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a …
- CVE-2017-12293HIGHCVSS 8.6EG 8.62017-10-19
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made…
- CVE-2017-12318HIGHCVSS 7.5EG 7.52017-11-16
A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting i…
- CVE-2017-12741HIGHCVSS 7.5EG 7.52017-12-26
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
- CVE-2017-12804MEDIUMCVSS 6.5EG 6.52019-05-09
The iwgif_init_screen function in imagew-gif.c:510 in ImageWorsener 1.3.2 allows remote attackers to cause a denial of service (hmemory exhaustion) via a crafted file.
- CVE-2017-12805HIGHCVSS 7.5EG 7.52019-05-09
In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function ReadTIFFImage, which allows attackers to cause a denial of service.
- CVE-2017-12806HIGHCVSS 7.5EG 7.52019-05-09
In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function format8BIM, which allows attackers to cause a denial of service.
- CVE-2017-13211HIGHCVSS 7.5EG 7.52018-01-12
In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received. This could lead to a remote denial of service of a critical system process with no addit…
- CVE-2017-13233MEDIUMCVSS 6.5EG 6.52018-02-12
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation.…
- CVE-2017-13825HIGHCVSS 7.8EG 7.82017-11-13
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a …
- CVE-2017-14028HIGHCVSS 7.5EG 7.52017-11-16
A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be a…
- CVE-2017-14086HIGHCVSS 7.5EG 7.52017-10-06
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, w…
- CVE-2017-14108MEDIUMCVSS 5.5EG 5.52017-09-05
libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters.
- CVE-2017-14137HIGHCVSS 7.5EG 7.52017-09-04
ReadWEBPImage in coders/webp.c in ImageMagick 7.0.6-5 has an issue where memory allocation is excessive because it depends only on a length field in a header.
- CVE-2017-14158HIGHCVSS 7.5EG 7.52017-09-05
Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separ…
- CVE-2017-14177HIGHCVSS 7.8EG 7.82018-02-02
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain ro…
- CVE-2017-14179HIGHCVSS 7.8EG 7.82018-02-02
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gai…
- CVE-2017-14180HIGHCVSS 7.8EG 7.82018-02-02
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or po…
- CVE-2017-14223MEDIUMCVSS 6.5EG 6.52017-09-09
In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not c…
- CVE-2017-14341MEDIUMCVSS 6.5EG 6.52017-09-12
ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
- CVE-2017-14342MEDIUMCVSS 6.5EG 6.52017-09-12
ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.
- CVE-2017-14360HIGHCVSS 7.5EG 7.52017-11-08
A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS).
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →