Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,411 CVEs tagged with CWE-40062 Critical, 1,673 High, 1,537 Medium, 137 Low, 2 Unrated.

CVE-2018-16491

Published Feb 1, 2019

A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16490

Published Feb 1, 2019

A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16487

Published Feb 1, 2019

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Objec…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6986

Published Jan 28, 2019

SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1644

Published Jan 23, 2019

A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to exhaust system resources, resu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3144

Published Jan 16, 2019

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2019-3554

Published Jan 15, 2019

Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connec…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15464

Published Jan 11, 2019

A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6347

Published Dec 31, 2018

An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6346

Published Dec 31, 2018

A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6335

Published Dec 31, 2018

A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of H…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20543

Published Dec 28, 2018

There is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXSMM 1.10 that will cause a denial of service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20502

Published Dec 26, 2018

An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_HvccAtom::Create in Core/Ap4HvccAt…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19871

Published Dec 26, 2018

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9732

Published Dec 20, 2018

The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, pos…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000872

Published Dec 20, 2018

OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20186

Published Dec 17, 2018

An issue was discovered in Bento4 1.5.1-627. AP4_Sample::ReadData in Core/Ap4Sample.cpp allows attackers to trigger an attempted excessive memory allocation, related to AP4_DataBu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6707

Published Dec 14, 2018

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, une…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 2,951-2,975 of 3,411 CVEsPage 119 of 137