VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

623 CVEsRSS

CVE-2025-5024High· 7.4
1y ago

A flaw was found in gnome-remote-desktop

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, …

▾ TwilightEPSS 0.82%via NVD
CVE-2024-52980Medium· 6.5
1y ago

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

▾ Sunlitelasticsearch · org.elasticsearch:elasticsearch-grokEPSS 0.54%via GHSA
CVE-2025-2586High· 7.5
1y ago

A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding

A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This iss…

▾ TwilightEPSS 0.53%via NVD
CVE-2024-12254High· 7.5
1y ago

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark". Because of t…

▾ TwilightEPSS 1.9%via NVD
CVE-2024-21536High· 7.5
1y ago

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process …

▾ Twilightchimurai · http-proxy-middlewareEPSS 1.0%via NVD
CVE-2024-8418High· 7.5
2y ago

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to b…

▾ Twilightcontainers · aardvark-dnsEPSS 0.77%via NVD
CVE-2024-45163Critical· 9.1PoC
2y ago

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized usern…

▾ AbyssalEPSS 0.77%via NVD
CVE-2023-39329Medium· 6.5
2y ago

A flaw was found in OpenJPEG

A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.

▾ Sunlituclouvain · openjpegEPSS 0.59%via NVD
CVE-2023-39327Medium· 4.3
2y ago

A flaw was found in OpenJPEG

A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.

▾ Sunlituclouvain · openjpegEPSS 0.56%via NVD
CVE-2023-39328Medium· 5.5
2y ago

A vulnerability was found in OpenJPEG similar to CVE-2019-6988

A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.

▾ Sunlituclouvain · openjpegEPSS 0.24%via NVD
CVE-2024-34045High· 7.5
2y ago

The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().

The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().

▾ TwilightEPSS 0.52%via NVD
CVE-2023-5685High· 7.5
2y ago

A flaw was found in XNIO

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

▾ TwilightRed Hat · xnioEPSS 3.5%via NVD
CVE-2024-1635High· 7.5
2y ago

A vulnerability was found in Undertow

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the conne…

▾ Twilightnetapp · active_iq_unified_managerEPSS 4.6%via NVD
CVE-2024-1014Medium· 6.2
2y ago

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets.

▾ Sunlitse-elektronic · e-ddc3.3_firmwareEPSS 0.71%via NVD
CVE-2024-0241High· 7.5
2y ago

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely…

▾ Twilightdiaconou · encodedid::railsEPSS 1.1%via NVD
CVE-2023-32611Medium· 5.5
3y ago

A flaw was found in GLib

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

▾ Sunlitgnome · glibEPSS 0.38%via NVD
CVE-2023-29544Medium· 6.5
3y ago

If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash

If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 1…

▾ Sunlitmozilla · firefoxEPSS 0.45%via NVD
CVE-2023-25153Medium· 5.5
3y ago

containerd: OCI image importer memory exhaustion (CVE-2023-25153)

A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.

▾ SunlitRed Hat · Red Hat Ceph Storage 9.0 ToolsEPSS 0.36%via CSAF
CVE-2022-23524High· 7.5⚖ disputed
3y ago

helm: Denial of service through string value parsing (CVE-2022-23524)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…

▾ TwilightRed Hat · RHACS 4.0 for RHEL 8EPSS 0.78%via CSAF
CVE-2022-38266Medium· 6.5
4y ago

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

▾ Sunlittesseract-ocr · tesseract_ocrEPSS 1.4%via NVD
CVE-2022-3064High· 7.5
4y ago

go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)

A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 1.7%via CSAF
CVE-2022-23328High· 7.5
4y ago

A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all o…

A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all o…

▾ Twilightethereum · go_ethereumEPSS 1.4%via NVD
CVE-2002-20001High· 7.5PoC
4y ago

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)a…

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)a…

▾ Midnightbalasys · dheaterEPSS 25%via NVD
CVE-2020-3572High· 8.6
5y ago

A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condi…

A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condi…

▾ Twilightcisco · adaptive_security_applianceEPSS 1.8%via NVD
CVE-2020-3571High· 8.6
5y ago

A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an…

A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.4%via NVD
CVE-2020-3563High· 8.6
5y ago

A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device

A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.4%via NVD
CVE-2020-3554High· 7.5
5y ago

A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…

A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…

▾ Twilightcisco · adaptive_security_applianceEPSS 2.7%via NVD
CVE-2020-3533High· 8.6
5y ago

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly.…

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly.…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.8%via NVD
CVE-2020-3529High· 8.6
5y ago

A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected de…

A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected de…

▾ Twilightcisco · adaptive_security_applianceEPSS 1.9%via NVD
CVE-2020-3528High· 8.6
5y ago

A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected devi…

A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected devi…

▾ Twilightcisco · adaptive_security_applianceEPSS 1.4%via NVD
CWE-400 vulnerabilities (CVEs) — page 20 · VulnSea