CWE-400— Uncontrolled Resource Consumption (Denial of Service)
3,210 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 5 of 65
- CVE-2017-6153MEDIUMCVSS 5.3EG 5.32018-06-01
Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly, via an iRule, or via the inflate code from PEM module are subjected to a service disrupt…
- CVE-2017-6198MEDIUMCVSS 6.5EG 6.52018-02-06
The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sandbox, or by using a large amount of disk space.
- CVE-2017-6779HIGHCVSS 7.5EG 7.52018-06-07
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in…
- CVE-2017-7651HIGHCVSS 7.5EG 7.52018-04-24
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.
- CVE-2017-9104CRITICALCVSS 9.8EG 9.82020-06-18
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
- CVE-2017-9732HIGHCVSS 7.5EG 7.52018-12-20
The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, possibly affecting another services running on the targeted hos…
- CVE-2018-0004MEDIUMCVSS 6.5EG 6.52018-01-10
A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific command is issued t…
- CVE-2018-0022HIGHCVSS 7.5EG 7.52018-04-11
A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS packet. Approximately 1 mbuf is leaked per each packet processed. The number of mbufs is pla…
- CVE-2018-0029MEDIUMCVSS 5.7EG 6.52018-07-11
While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore). This issue only affects Junos OS 15.1 and later releases, a…
- CVE-2018-0030HIGHCVSS 7.5EG 7.52018-07-11
Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart. By continuously sending specific MPLS packets, an attacker can repeatedly crash the line cards or PTX1K causing a sus…
- CVE-2018-0031MEDIUMCVSS 5.3EG 5.92018-07-11
Receipt of specially crafted UDP/IP packets over MPLS may be able to bypass a stateless firewall filter. The crafted UDP packets must be encapsulated and meet a very specific packet format to be classified in a way that bypasses IP firewal…
- CVE-2018-0048HIGHCVSS 7.5EG 7.52018-10-10
A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker to cause a severe memory exhaustion condition on the device. This can have an adverse imp…
- CVE-2018-0054MEDIUMCVSS 6.5EG 6.52018-10-10
On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the management interface (fxp0) can cause egress interface congestion, resulting in routing protocol packet drops, such as BGP, …
- CVE-2018-0061MEDIUMCVSS 5.3EG 5.32018-10-10
A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system performance. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior t…
- CVE-2018-0063MEDIUMCVSS 6.5EG 6.52018-10-10
A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust the private Internal routing interfaces (IRIs) next-hop limit. Once the IRI next-hop datab…
- CVE-2018-0086HIGHCVSS 8.6EG 8.62018-01-18
A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to mal…
- CVE-2018-0090HIGHCVSS 7.5EG 7.52018-01-18
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic …
- CVE-2018-0094HIGHCVSS 7.5EG 7.52018-01-18
A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device. The vulnerabi…
- CVE-2018-0230HIGHCVSS 8.6EG 8.62018-04-19
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected devic…
- CVE-2018-0233HIGHCVSS 8.6EG 8.62018-04-19
A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive…
- CVE-2018-0285MEDIUMCVSS 6.5EG 6.52018-05-02
A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interface. The vulnerability is due to exhaustion of disk space. An attacker could exploit this vu…
- CVE-2018-0309HIGHCVSS 7.7EG 7.72018-06-21
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authent…
- CVE-2018-0372HIGHCVSS 7.5EG 7.52018-07-18
A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which co…
- CVE-2018-0381MEDIUMCVSS 6.8EG 6.82018-10-17
A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerabilit…
- CVE-2018-0410HIGHCVSS 8.6EG 8.62018-08-15
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affecte…
- CVE-2018-0418HIGHCVSS 8.6EG 8.62018-08-15
A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affe…
- CVE-2018-0441HIGHCVSS 7.4EG 7.42018-10-17
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is…
- CVE-2018-0471HIGHCVSS 7.4EG 7.42018-10-05
A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition.…
- CVE-2018-0700HIGHCVSS 7.5EG 7.52018-11-15
YukiWiki 2.1.3 and earlier does not process a particular request properly that may allow consumption of large amounts of CPU and memory resources and may result in causing a denial of service condition.
- CVE-2018-1000115HIGHCVSS 7.5EG 7.52018-03-05
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic am…
- CVE-2018-1000518HIGHCVSS 7.5EG 7.52018-06-26
aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memor…
- CVE-2018-1000872MEDIUMCVSS 6.5EG 6.52018-12-20
OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can be made unavailable by one or more clie…
- CVE-2018-1000891HIGHCVSS 7.5EG 7.52020-12-23
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.
- CVE-2018-1000892HIGHCVSS 7.5EG 7.52020-12-23
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.
- CVE-2018-1000893HIGHCVSS 7.5EG 7.52020-12-23
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.
- CVE-2018-10070HIGHCVSS 7.5EG 7.52018-04-16
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the …
- CVE-2018-10193HIGHCVSS 7.5EG 7.52018-04-18
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.
- CVE-2018-10432HIGHCVSS 7.5EG 7.52020-09-25
Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
- CVE-2018-10585HIGHCVSS 7.5EG 7.52020-09-25
Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
- CVE-2018-10607HIGHCVSS 7.5EG 7.52018-07-31
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, which may cause a denial of service within the industrial proc…
- CVE-2018-10608HIGHCVSS 7.5EG 7.52018-07-24
SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization. Restart of the application is r…
- CVE-2018-10632HIGHCVSS 7.5EG 7.52018-07-24
In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.
- CVE-2018-1064HIGHCVSS 7.5EG 7.52018-03-28
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
- CVE-2018-10827HIGHCVSS 7.5EG 7.52018-05-09
LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bound, and is loaded into memory for each request.
- CVE-2018-10851MEDIUMCVSS 5.3EG 7.52018-11-29
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of s…
- CVE-2018-10864MEDIUMCVSS 5.3EG 6.22018-08-13
An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide an existing but invalid XML file which would be opened and never closed, possibly producin…
- CVE-2018-10868HIGHCVSS 7.5EG 7.52021-05-26
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of a…
- CVE-2018-10924MEDIUMCVSS 5.3EG 6.52018-09-04
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
- CVE-2018-10935MEDIUMCVSS 6.5EG 6.52018-09-11
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
- CVE-2018-11056MEDIUMCVSS 6.5EG 6.52018-08-31
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 dat…
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →