Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,267 CVEs tagged with CWE-40059 Critical, 1,606 High, 1,466 Medium, 134 Low, 2 Unrated.

CVE-2018-10827

Published May 9, 2018

LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0285

Published May 2, 2018

A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interface. The vulnerability is due to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0233

Published Apr 19, 2018

A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10193

Published Apr 18, 2018

LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows wit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10070

Published Apr 16, 2018

A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on po…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1064

Published Mar 28, 2018

libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEM…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2885

Published Mar 19, 2018

Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9589

Published Mar 12, 2018

Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in per…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7876

Published Mar 8, 2018

In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18214

Published Mar 4, 2018

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7651

Published Mar 4, 2018

index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7048

Published Mar 1, 2018

An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,976-3,000 of 3,267 CVEsPage 120 of 131