Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,267 CVEs tagged with CWE-40059 Critical, 1,606 High, 1,466 Medium, 134 Low, 2 Unrated.

CVE-2017-1000359

Published Apr 24, 2017

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are Open…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000357

Published Apr 24, 2017

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the featu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2333

Published Apr 24, 2017

A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2327

Published Apr 24, 2017

A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to consume l…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7940

Published Apr 18, 2017

The iw_read_gif_file function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3104

Published Apr 14, 2017

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3885

Published Apr 7, 2017

A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cau…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7397

Published Apr 3, 2017

BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8780

Published Apr 2, 2017

Huawei CloudEngine 6800 V100R006C00, CloudEngine 7800 V100R006C00, CloudEngine 8800 V100R006C00, and CloudEngine 12800 V100R006C00 allow remote attackers with specific permission…

CVSS 6.5 · Medium

CVE-2017-7285

Published Mar 29, 2017

A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2225

Published Mar 24, 2017

The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2224

Published Mar 24, 2017

The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compress…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10058

Published Mar 23, 2017

Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick before 6.9.6-3 allows remote attackers to cause a denial of service (memory consumption) via a crafted ima…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10047

Published Mar 23, 2017

Memory leak in the NewXMLTree function in magick/xml-tree.c in ImageMagick before 6.9.4-7 allows remote attackers to cause a denial of service (memory consumption) via a crafted X…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3857

Published Mar 22, 2017

A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 through 15.6) and Cisco IOS XE (3.1 through 3.18) could allow an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3856

Published Mar 22, 2017

A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9643

Published Mar 7, 2017

The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) fol…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5867

Published Mar 3, 2017

ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service (server hang and logfi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,126-3,150 of 3,267 CVEsPage 126 of 131