CWE-399
447 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-399page 1 of 9
- CVE-2000-0305HIGHCVSS v2 7.8EG 7.82000-05-19
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" …
- CVE-2001-0041HIGHCVSS v2 7.8EG 7.82001-02-16
Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.
- CVE-2002-1024HIGHCVSS v2 7.1EG 7.12002-10-04
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
- CVE-2002-1203MEDIUMCVSS v2 5.0EG 5.02002-10-28
IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packet…
- CVE-2002-2241MEDIUMCVSS v2 5.0EG 5.02002-12-31
Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request.
- CVE-2002-2306HIGHCVSS v2 7.8EG 7.82002-12-31
Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages.
- CVE-2002-2309HIGHCVSS v2 7.8EG 7.82002-12-31
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
- CVE-2003-0792MEDIUMCVSS v2 5.0EG 5.02003-11-17
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.
- CVE-2003-0858LOWCVSS v2 2.1EG 2.12003-12-15
Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
- CVE-2003-1320MEDIUMCVSS v2 5.1EG 5.12003-12-31
SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (S…
- CVE-2003-1342MEDIUMCVSS v2 5.0EG 5.02003-12-31
Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe.
- CVE-2003-1421MEDIUMCVSS v2 4.3EG 4.32003-12-31
Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.
- CVE-2003-1448HIGHCVSS v2 7.8EG 7.82003-12-31
Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.
- CVE-2003-1494MEDIUMCVSS v2 5.0EG 5.02003-12-31
Unspecified vulnerability in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (CPU consumption) via a crafted TCP packet.
- CVE-2004-0478LOWCVSS v2 2.6EG 2.62004-07-07
Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control character…
- CVE-2004-0918MEDIUMCVSS v2 5.0EG 5.02005-01-27
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger …
- CVE-2004-1759MEDIUMCVSS v2 5.0EG 5.02004-01-21
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scannin…
- CVE-2004-1848MEDIUMCVSS v2 5.0EG 5.02004-12-31
Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.
- CVE-2004-2779HIGHCVSS 7.5EG 7.52018-02-20
id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless loop allocating memory until an OOM condition is reached, leading to denial-of-servic…
- CVE-2005-0210MEDIUMCVSS v2 4.9EG 4.92005-05-02
Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.
- CVE-2005-1126LOWCVSS v2 2.1EG 2.12005-04-15
The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.
- CVE-2010-0806CRITICALCVSS 8.8EG 9.0⚠ KEV2010-03-10
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the dele…
- CVE-2010-5329MEDIUMCVSS 5.5EG 5.52017-04-24
The video_usercopy function in drivers/media/video/v4l2-ioctl.c in the Linux kernel before 2.6.39 relies on the count value of a v4l2_ext_controls data structure to determine a kmalloc size, which might allow local users to cause a denial …
- CVE-2011-4650HIGHCVSS 7.5EG 7.52017-08-07
Cisco Data Center Network Manager is affected by Excessive Logging During a TCP Flood on Java Ports. If the size of server.log becomes very big because of too much logging by the DCNM server, then the CPU utilization increases. Known Affec…
- CVE-2012-0880HIGHCVSS 7.5EG 7.52017-08-08
Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.
- CVE-2012-0881HIGHCVSS 7.5EG 7.52017-10-30
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
- CVE-2012-5030MEDIUMCVSS 6.5EG 6.52017-08-02
Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote authenticated users to cause a denial of service (CPU consumption, watchdog timeout, crash) by walking specific SNMP objects.
- CVE-2012-6435HIGHCVSS 7.5EG 7.82013-01-24
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a Do…
- CVE-2012-6697HIGHCVSS 7.5EG 7.52017-04-13
InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).
- CVE-2014-10064HIGHCVSS 7.5EG 7.52018-05-31
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to …
- CVE-2014-3221HIGHCVSS 7.5EG 7.52017-04-02
Huawei Eudemon8000E firewall with software V200R001C01SPC800 and earlier versions allows users to log in to the device using Telnet or SSH. When an attacker sends to the device a mass of TCP packets with special structure, the logging proc…
- CVE-2014-3224HIGHCVSS 7.5EG 7.52017-04-02
Huawei Quidway S9700 V200R003C00SPC500, Quidway S9300 V200R003C00SPC500, Quidway S7700 V200R003C00SPC500, Quidway S6700 V200R003C00SPC300, Quidway S6300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300 en…
- CVE-2014-6438HIGHCVSS 7.5EG 7.52017-09-06
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.
- CVE-2014-8171MEDIUMCVSS 5.5EG 5.52018-02-09
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
- CVE-2014-9637MEDIUMCVSS 5.5EG 5.52017-08-25
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
- CVE-2014-9686MEDIUMCVSS 5.9EG 5.92017-09-28
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerab…
- CVE-2014-9747HIGHCVSS 7.5EG 7.52016-06-07
The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 f…
- CVE-2014-9848HIGHCVSS 7.5EG 7.52017-03-20
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
- CVE-2014-9850HIGHCVSS 7.5EG 7.52017-03-20
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
- CVE-2014-9853MEDIUMCVSS 5.5EG 5.52017-03-17
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
- CVE-2014-9854HIGHCVSS 7.5EG 7.52017-03-17
coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
- CVE-2015-0718HIGHCVSS 7.5EG 7.52016-03-03
Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a de…
- CVE-2015-1339MEDIUMCVSS 6.2EG 6.22016-04-27
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many time…
- CVE-2015-1832CRITICALCVSS 9.1EG 9.12016-10-03
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resourc…
- CVE-2015-2927MEDIUMCVSS 6.5EG 6.52017-09-20
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
- CVE-2015-4942MEDIUMCVSS 5.3EG 5.32016-01-18
IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4943.
- CVE-2015-5162HIGHCVSS 7.5EG 7.52016-10-07
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory…
- CVE-2015-5187MEDIUMCVSS 6.5EG 6.52017-07-25
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
- CVE-2015-5332MEDIUMCVSS 6.8EG 6.82016-02-22
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
- CVE-2015-5516HIGHCVSS 7.5EG 7.52016-01-20
Memory leak in the last hop kernel module in F5 BIG-IP LTM, GTM, and Link Controller 10.1.x, 10.2.x before 10.2.4 HF13, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x, 11.5.x before 11.5.3 HF2, and 11.6.x before HF6, BIG-IP AAM 11.4.x, 11.5.x bef…
Map vulnerabilities like CWE-399 to your infrastructure
EchelonGraph correlates every CVE — across CWE-399 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →