Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,411 CVEs tagged with CWE-40062 Critical, 1,673 High, 1,537 Medium, 137 Low, 2 Unrated.

CVE-2019-0199

Published Apr 10, 2019

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep str…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4080

Published Apr 2, 2019

IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13296

Published Apr 1, 2019

Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct denial-of-service attacks via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5739

Published Mar 28, 2019

Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5737

Published Mar 28, 2019

In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1737

Published Mar 27, 2019

A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE software could allow an unauthenticated, remote attacker to ca…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4046

Published Mar 25, 2019

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3874

Published Mar 25, 2019

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x…

CVSS 6.5 · Medium

CVE-2018-19158

Published Mar 21, 2019

ColossusCoinXT through 1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9750

Published Mar 13, 2019

In IoTivity through 1.3.1, the CoAP server interface can be used for Distributed Denial of Service attacks using source IP address spoofing and UDP-based traffic amplification. Th…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9587

Published Mar 6, 2019

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5819

Published Feb 20, 2019

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20030

Published Feb 20, 2019

An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8909

Published Feb 18, 2019

An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1672

Published Feb 8, 2019

A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configu…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16492

Published Feb 1, 2019

A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,926-2,950 of 3,411 CVEsPage 118 of 137