Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,439 CVEs tagged with CWE-40062 Critical, 1,687 High, 1,549 Medium, 138 Low, 3 Unrated.

CVE-2017-0690

Published Jul 6, 2017

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36592202.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10922

Published Jul 5, 2017

The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XS…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10800

Published Jul 3, 2017

When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10799

Published Jul 3, 2017

When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7521

Published Jun 27, 2017

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_ex…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6043

Published Jun 21, 2017

A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-9129

Published Jun 21, 2017

The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav fil…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000378

Published Jun 19, 2017

The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000373

Published Jun 19, 2017

The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5004

Published Jun 6, 2017

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2535

Published May 22, 2017

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers to conduct sandbox-escape att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8338

Published May 18, 2017

A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8327

Published Apr 29, 2017

The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2322

Published Apr 24, 2017

A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread d…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000359

Published Apr 24, 2017

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are Open…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000357

Published Apr 24, 2017

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the featu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2333

Published Apr 24, 2017

A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,276-3,300 of 3,439 CVEsPage 132 of 138