Skip to main content

CWE archive

CWE-399 CVEs

Programmatic archive

2,694 CVEs tagged with CWE-399467 Critical, 830 High, 1,300 Medium, 97 Low, 0 Unrated.

CVE-2016-6173

Published Feb 9, 2017

NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10153

Published Feb 6, 2017

The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6188

Published Feb 3, 2017

Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment, related to tempora…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6235

Published Feb 2, 2017

The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8919

Published Feb 1, 2017

IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resourc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5434

Published Jan 30, 2017

libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7544

Published Jan 30, 2017

Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5822

Published Jan 27, 2017

Huawei Oceanstor 5800 before V300R002C10SPC100 allows remote attackers to cause a denial of service (CPU consumption) via a large number of crafted HTTP packets.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9221

Published Jan 26, 2017

A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthentica…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9220

Published Jan 26, 2017

A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9216

Published Jan 26, 2017

An IKE Packet Parsing Denial of Service Vulnerability in the ipsecmgr process of Cisco ASR 5000 Software could allow an unauthenticated, remote attacker to cause the ipsecmgr proc…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6160

Published Jan 23, 2017

tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a large frame, a related issue to CVE-2017-14266.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8858

Published Jan 23, 2017

The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8855

Published Jan 23, 2017

The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9312

Published Jan 13, 2017

ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-8883

Published Jan 13, 2017

The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8463

Published Jan 12, 2017

A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is r…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6767

Published Jan 12, 2017

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6764

Published Jan 12, 2017

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6581

Published Jan 10, 2017

A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called "H…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6580

Published Jan 10, 2017

A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority inf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 226-250 of 2,694 CVEsPage 10 of 108