CWE-404
Allowed-with-ReviewImproper Resource Shutdown or Release
Abstraction: Class · Status: Draft
The product does not release or incorrectly releases a resource before it is made available for re-use.
1365 vulnerabilities reference this CWE, most recent first.
CVE-2026-103241 (GCVE-0-2026-103241)
Vulnerability from cvelistv5 – Published: 2026-09-30 16:45 – Updated: 2026-09-30 16:45 X_Open Source- CWE-404 - Denial of Service
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/411965 | vdb-entry |
| https://vuldb.com/vuln/411965/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103241 | third-party-advisory |
| https://vuldb.com/submit/956250 | third-party-advisory |
| https://github.com/vllm-project/vllm/issues/50927 | issue-tracking |
| https://github.com/vllm-project/vllm/pull/54303 | issue-trackingpatch |
| https://gist.github.com/Yunzez/8e98d656aa667095b5… | exploit |
| https://github.com/vllm-project/vllm/commit/3439b… | patch |
| https://github.com/vllm-project/vllm/releases/tag… | patch |
| https://github.com/vllm-project/vllm/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| vllm-project | vLLM |
Affected:
0.1
Affected: 0.2 Affected: 0.3 Affected: 0.4 Affected: 0.5 Affected: 0.6 Affected: 0.7 Affected: 0.8 Affected: 0.9 Affected: 0.10 Affected: 0.11 Affected: 0.12 Affected: 0.13 Affected: 0.14 Affected: 0.15 Affected: 0.16 Affected: 0.17 Affected: 0.18 Affected: 0.19 Affected: 0.20 Affected: 0.21 Affected: 0.22 Affected: 0.23 Affected: 0.24 Affected: 0.25 Affected: 0.26.0 Unaffected: 0.29.1rc0 cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:*"
],
"modules": [
"Gemma4UnifiedParser"
],
"product": "vLLM",
"vendor": "vllm-project",
"versions": [
{
"status": "affected",
"version": "0.1"
},
{
"status": "affected",
"version": "0.2"
},
{
"status": "affected",
"version": "0.3"
},
{
"status": "affected",
"version": "0.4"
},
{
"status": "affected",
"version": "0.5"
},
{
"status": "affected",
"version": "0.6"
},
{
"status": "affected",
"version": "0.7"
},
{
"status": "affected",
"version": "0.8"
},
{
"status": "affected",
"version": "0.9"
},
{
"status": "affected",
"version": "0.10"
},
{
"status": "affected",
"version": "0.11"
},
{
"status": "affected",
"version": "0.12"
},
{
"status": "affected",
"version": "0.13"
},
{
"status": "affected",
"version": "0.14"
},
{
"status": "affected",
"version": "0.15"
},
{
"status": "affected",
"version": "0.16"
},
{
"status": "affected",
"version": "0.17"
},
{
"status": "affected",
"version": "0.18"
},
{
"status": "affected",
"version": "0.19"
},
{
"status": "affected",
"version": "0.20"
},
{
"status": "affected",
"version": "0.21"
},
{
"status": "affected",
"version": "0.22"
},
{
"status": "affected",
"version": "0.23"
},
{
"status": "affected",
"version": "0.24"
},
{
"status": "affected",
"version": "0.25"
},
{
"status": "affected",
"version": "0.26.0"
},
{
"status": "unaffected",
"version": "0.29.1rc0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Zyz3366 (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:45:13.581Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-411965 | vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/411965"
},
{
"name": "VDB-411965 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/411965/cti"
},
{
"name": "CVE-2026-103241 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103241"
},
{
"name": "Submit #956250 | vLLM Project vLLM v0.26.0 Denial of Service",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/956250"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/vllm-project/vllm/issues/50927"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/vllm-project/vllm/pull/54303"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/Yunzez/8e98d656aa667095b513161eb056d28e"
},
{
"tags": [
"patch"
],
"url": "https://github.com/vllm-project/vllm/commit/3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9"
},
{
"tags": [
"patch"
],
"url": "https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0"
},
{
"tags": [
"product"
],
"url": "https://github.com/vllm-project/vllm/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T12:42:01.000Z",
"value": "VulDB entry last update"
}
],
"title": "vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103241",
"datePublished": "2026-09-30T16:45:13.581Z",
"dateReserved": "2026-09-30T10:36:13.164Z",
"dateUpdated": "2026-09-30T16:45:13.581Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103118 (GCVE-0-2026-103118)
Vulnerability from cvelistv5 – Published: 2026-09-30 13:30 – Updated: 2026-09-30 13:30 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/411874 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/411874/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103118 | third-party-advisory |
| https://vuldb.com/submit/954970 | third-party-advisory |
| https://foss.heptapod.net/graphicsmagick/graphics… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | GraphicsMagick |
Affected:
1.3.0
Affected: 1.3.1 Affected: 1.3.2 Affected: 1.3.3 Affected: 1.3.4 Affected: 1.3.5 Affected: 1.3.6 Affected: 1.3.7 Affected: 1.3.8 Affected: 1.3.9 Affected: 1.3.10 Affected: 1.3.11 Affected: 1.3.12 Affected: 1.3.13 Affected: 1.3.14 Affected: 1.3.15 Affected: 1.3.16 Affected: 1.3.17 Affected: 1.3.18 Affected: 1.3.19 Affected: 1.3.20 Affected: 1.3.21 Affected: 1.3.22 Affected: 1.3.23 Affected: 1.3.24 Affected: 1.3.25 Affected: 1.3.26 Affected: 1.3.27 Affected: 1.3.28 Affected: 1.3.29 Affected: 1.3.30 Affected: 1.3.31 Affected: 1.3.32 Affected: 1.3.33 Affected: 1.3.34 Affected: 1.3.35 Affected: 1.3.36 Affected: 1.3.37 Affected: 1.3.38 Affected: 1.3.39 Affected: 1.3.40 Affected: 1.3.41 Affected: 1.3.42 Affected: 1.3.43 Affected: 1.3.44 Affected: 1.3.45 Affected: 1.3.46 Affected: 1.3.47 cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*"
],
"modules": [
"WPG File Handler"
],
"product": "GraphicsMagick",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "1.3.0"
},
{
"status": "affected",
"version": "1.3.1"
},
{
"status": "affected",
"version": "1.3.2"
},
{
"status": "affected",
"version": "1.3.3"
},
{
"status": "affected",
"version": "1.3.4"
},
{
"status": "affected",
"version": "1.3.5"
},
{
"status": "affected",
"version": "1.3.6"
},
{
"status": "affected",
"version": "1.3.7"
},
{
"status": "affected",
"version": "1.3.8"
},
{
"status": "affected",
"version": "1.3.9"
},
{
"status": "affected",
"version": "1.3.10"
},
{
"status": "affected",
"version": "1.3.11"
},
{
"status": "affected",
"version": "1.3.12"
},
{
"status": "affected",
"version": "1.3.13"
},
{
"status": "affected",
"version": "1.3.14"
},
{
"status": "affected",
"version": "1.3.15"
},
{
"status": "affected",
"version": "1.3.16"
},
{
"status": "affected",
"version": "1.3.17"
},
{
"status": "affected",
"version": "1.3.18"
},
{
"status": "affected",
"version": "1.3.19"
},
{
"status": "affected",
"version": "1.3.20"
},
{
"status": "affected",
"version": "1.3.21"
},
{
"status": "affected",
"version": "1.3.22"
},
{
"status": "affected",
"version": "1.3.23"
},
{
"status": "affected",
"version": "1.3.24"
},
{
"status": "affected",
"version": "1.3.25"
},
{
"status": "affected",
"version": "1.3.26"
},
{
"status": "affected",
"version": "1.3.27"
},
{
"status": "affected",
"version": "1.3.28"
},
{
"status": "affected",
"version": "1.3.29"
},
{
"status": "affected",
"version": "1.3.30"
},
{
"status": "affected",
"version": "1.3.31"
},
{
"status": "affected",
"version": "1.3.32"
},
{
"status": "affected",
"version": "1.3.33"
},
{
"status": "affected",
"version": "1.3.34"
},
{
"status": "affected",
"version": "1.3.35"
},
{
"status": "affected",
"version": "1.3.36"
},
{
"status": "affected",
"version": "1.3.37"
},
{
"status": "affected",
"version": "1.3.38"
},
{
"status": "affected",
"version": "1.3.39"
},
{
"status": "affected",
"version": "1.3.40"
},
{
"status": "affected",
"version": "1.3.41"
},
{
"status": "affected",
"version": "1.3.42"
},
{
"status": "affected",
"version": "1.3.43"
},
{
"status": "affected",
"version": "1.3.44"
},
{
"status": "affected",
"version": "1.3.45"
},
{
"status": "affected",
"version": "1.3.46"
},
{
"status": "affected",
"version": "1.3.47"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "zzxzzb (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:30:05.945Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-411874 | GraphicsMagick WPG File wpg.c ExtractPostscript recursion",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/411874"
},
{
"name": "VDB-411874 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/411874/cti"
},
{
"name": "CVE-2026-103118 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103118"
},
{
"name": "Submit #954970 | Graphicsmagick 1.3.47 and prior; fixed in development changeset 627b5b1b2fc2 (2026-08-24), not yet in any release Uncontrolled Recursion",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/954970"
},
{
"tags": [
"patch"
],
"url": "https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/627b5b1b2fc2"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T08:02:10.000Z",
"value": "VulDB entry last update"
}
],
"title": "GraphicsMagick WPG File wpg.c ExtractPostscript recursion",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103118",
"datePublished": "2026-09-30T13:30:05.945Z",
"dateReserved": "2026-09-30T05:57:03.831Z",
"dateUpdated": "2026-09-30T13:30:05.945Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101098 (GCVE-0-2026-101098)
Vulnerability from cvelistv5 – Published: 2026-09-28 17:00 – Updated: 2026-09-28 17:48| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410973 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410973/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101098 | third-party-advisory |
| https://vuldb.com/submit/934960 | third-party-advisory |
| https://github.com/ag-ui-protocol/ag-ui/issues/2441 | issue-tracking |
| https://github.com/ag-ui-protocol/ag-ui/pull/2671 | issue-trackingpatch |
| https://github.com/ag-ui-protocol/ag-ui/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| ag-ui-protocol | ag-ui |
Affected:
2026-09-23
cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101098",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T17:48:04.263858Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:48:21.413Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
],
"modules": [
"HTTP Handler"
],
"product": "ag-ui",
"vendor": "ag-ui-protocol",
"versions": [
{
"status": "affected",
"version": "2026-09-23"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "meraklbz (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:00:16.182Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410973 | ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410973"
},
{
"name": "VDB-410973 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410973/cti"
},
{
"name": "CVE-2026-101098 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101098"
},
{
"name": "Submit #934960 | ag-ui-protocol ag-ui v1.0 CWE-400",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/934960"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/ag-ui-protocol/ag-ui/issues/2441"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/ag-ui-protocol/ag-ui/pull/2671"
},
{
"tags": [
"product"
],
"url": "https://github.com/ag-ui-protocol/ag-ui/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-28T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-28T04:58:47.000Z",
"value": "VulDB entry last update"
}
],
"title": "ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101098",
"datePublished": "2026-09-28T17:00:16.182Z",
"dateReserved": "2026-09-28T02:53:30.772Z",
"dateUpdated": "2026-09-28T17:48:21.413Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101040 (GCVE-0-2026-101040)
Vulnerability from cvelistv5 – Published: 2026-09-28 11:00 – Updated: 2026-10-01 14:13- CWE-404 - Denial of Service
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410908 | vdb-entry |
| https://vuldb.com/vuln/410908/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101040 | third-party-advisory |
| https://vuldb.com/submit/927274 | third-party-advisory |
| https://vuldb.com/submit/927275 | third-party-advisory |
| https://vuldb.com/submit/927289 | third-party-advisory |
| https://vuldb.com/submit/927478 | third-party-advisory |
| https://github.com/xiaobor123/vuls-find-VxWorks/t… | related |
| https://github.com/xiaobor123/vuls-find-VxWorks/b… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Ricoh | SP 330DN |
Affected:
20260813
cpe:2.3:a:ricoh:sp_330dn:*:*:*:*:*:*:*:* |
|
| Ricoh | SP 221 |
Affected:
20260813
cpe:2.3:a:ricoh:sp_221:*:*:*:*:*:*:*:* |
|
| Ricoh | SP C252SF |
Affected:
20260813
cpe:2.3:a:ricoh:sp_c252sf:*:*:*:*:*:*:*:* |
|
| Ricoh | Aficio SP 3500SF |
Affected:
20260813
cpe:2.3:a:ricoh:aficio_sp_3500sf:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101040",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:13:30.430729Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:13:40.410Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ricoh:sp_330dn:*:*:*:*:*:*:*:*"
],
"modules": [
"HTTP Multipart Form-Data Parser"
],
"product": "SP 330DN",
"vendor": "Ricoh",
"versions": [
{
"status": "affected",
"version": "20260813"
}
]
},
{
"cpes": [
"cpe:2.3:a:ricoh:sp_221:*:*:*:*:*:*:*:*"
],
"modules": [
"HTTP Multipart Form-Data Parser"
],
"product": "SP 221",
"vendor": "Ricoh",
"versions": [
{
"status": "affected",
"version": "20260813"
}
]
},
{
"cpes": [
"cpe:2.3:a:ricoh:sp_c252sf:*:*:*:*:*:*:*:*"
],
"modules": [
"HTTP Multipart Form-Data Parser"
],
"product": "SP C252SF",
"vendor": "Ricoh",
"versions": [
{
"status": "affected",
"version": "20260813"
}
]
},
{
"cpes": [
"cpe:2.3:a:ricoh:aficio_sp_3500sf:*:*:*:*:*:*:*:*"
],
"modules": [
"HTTP Multipart Form-Data Parser"
],
"product": "Aficio SP 3500SF",
"vendor": "Ricoh",
"versions": [
{
"status": "affected",
"version": "20260813"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "xiaobor123 (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.8,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:C/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T11:00:13.020Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410908 | Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data denial of service",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/410908"
},
{
"name": "VDB-410908 | CTI Indicators (IOB, IOC, TTP)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410908/cti"
},
{
"name": "CVE-2026-101040 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101040"
},
{
"name": "Submit #927274 | RICOH RICOH SP 330DN V1.11 Denial of Service",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/927274"
},
{
"name": "Submit #927275 | RICOH SP 221 V1.02 Denial of Service (Duplicate)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/927275"
},
{
"name": "Submit #927289 | RICOH SP C252SF V1.17 Denial of Service (Duplicate)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/927289"
},
{
"name": "Submit #927478 | RICOH Aficio SP 3500SF V2.14 Stack-based Buffer Overflow (Duplicate)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/927478"
},
{
"tags": [
"related"
],
"url": "https://github.com/xiaobor123/vuls-find-VxWorks/tree/main/RICOH/03-SP330DN-multipart-parser-infinite-loop"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/xiaobor123/vuls-find-VxWorks/blob/main/RICOH/03-SP330DN-multipart-parser-infinite-loop/poc.py"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-28T11:53:59.000Z",
"value": "VulDB entry last update"
}
],
"title": "Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data denial of service",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101040",
"datePublished": "2026-09-28T11:00:13.020Z",
"dateReserved": "2026-09-27T14:33:04.218Z",
"dateUpdated": "2026-10-01T14:13:40.410Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100895 (GCVE-0-2026-100895)
Vulnerability from cvelistv5 – Published: 2026-09-28 01:15 – Updated: 2026-09-28 13:00| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410845 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410845/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100895 | third-party-advisory |
| https://vuldb.com/submit/917187 | third-party-advisory |
| https://weitongli.com/share/openarc-c-tag-null-de… | exploit |
| https://github.com/trusteddomainproject/OpenARC/r… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| Trusted Domain Project | OpenARC |
Affected:
1.0.0.Beta1
Unaffected: 1.0.0.Beta0 cpe:2.3:a:trusted_domain_project:openarc:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100895",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:56:36.439752Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:00:11.969Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:trusted_domain_project:openarc:*:*:*:*:*:*:*:*"
],
"modules": [
"libopenarc"
],
"product": "OpenARC",
"vendor": "Trusted Domain Project",
"versions": [
{
"status": "affected",
"version": "1.0.0.Beta1"
},
{
"status": "unaffected",
"version": "1.0.0.Beta0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "WeitongLi (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "NULL Pointer Dereference",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T01:15:11.424Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410845 | Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410845"
},
{
"name": "VDB-410845 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410845/cti"
},
{
"name": "CVE-2026-100895 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100895"
},
{
"name": "Submit #917187 | The Trusted Domain Project OpenARC 1.0.0 NULL Pointer Dereference",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/917187"
},
{
"tags": [
"exploit"
],
"url": "https://weitongli.com/share/openarc-c-tag-null-deref.html"
},
{
"tags": [
"patch"
],
"url": "https://github.com/trusteddomainproject/OpenARC/releases/tag/v1.0.0.Beta0"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:27:14.000Z",
"value": "VulDB entry last update"
}
],
"title": "Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100895",
"datePublished": "2026-09-28T01:15:11.424Z",
"dateReserved": "2026-09-27T08:22:09.540Z",
"dateUpdated": "2026-09-28T13:00:11.969Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100890 (GCVE-0-2026-100890)
Vulnerability from cvelistv5 – Published: 2026-09-28 00:00 – Updated: 2026-09-28 12:55| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410840 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410840/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100890 | third-party-advisory |
| https://vuldb.com/submit/917188 | third-party-advisory |
| https://weitongli.com/share/opendmarc-ip6-wild-po… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Trusted Domain Project | OpenDMARC |
Affected:
1.4.0
Affected: 1.4.1 Affected: 1.4.2 cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100890",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:55:04.151218Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:55:20.361Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*"
],
"modules": [
"SPF Parser"
],
"product": "OpenDMARC",
"vendor": "Trusted Domain Project",
"versions": [
{
"status": "affected",
"version": "1.4.0"
},
{
"status": "affected",
"version": "1.4.1"
},
{
"status": "affected",
"version": "1.4.2"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "WeitongLi (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "NULL Pointer Dereference",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T00:00:12.540Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410840 | Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereference",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410840"
},
{
"name": "VDB-410840 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410840/cti"
},
{
"name": "CVE-2026-100890 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100890"
},
{
"name": "Submit #917188 | The Trusted Domain Project OpenDMARC 1.4.2 NULL Pointer Dereference",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/917188"
},
{
"tags": [
"exploit"
],
"url": "https://weitongli.com/share/opendmarc-ip6-wild-pointer.html"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T10:00:20.000Z",
"value": "VulDB entry last update"
}
],
"title": "Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereference",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100890",
"datePublished": "2026-09-28T00:00:12.540Z",
"dateReserved": "2026-09-27T07:55:10.374Z",
"dateUpdated": "2026-09-28T12:55:20.361Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94137 (GCVE-0-2026-94137)
Vulnerability from cvelistv5 – Published: 2026-09-21 03:15 – Updated: 2026-09-24 13:14- CWE-404 - Denial of Service
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408054 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408054/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-94137 | third-party-advisory |
| https://vuldb.com/submit/893882 | third-party-advisory |
| https://www.virustotal.com/gui/file/e3b99f727e59a… | related |
| Vendor | Product | Version | |
|---|---|---|---|
| Hangzhou Shunwang Technology | shzh |
Affected:
10.7.2.693
cpe:2.3:a:hangzhou_shunwang_technology:shzh:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94137",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:14:29.083605Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T13:14:39.259Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:hangzhou_shunwang_technology:shzh:*:*:*:*:*:*:*:*"
],
"modules": [
"IRP_MJ_DEVICE_CONTROL Handler"
],
"product": "shzh",
"vendor": "Hangzhou Shunwang Technology",
"versions": [
{
"status": "affected",
"version": "10.7.2.693"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Element2023H (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation of the argument PID leads to denial of service. The attack must be carried out locally."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 3.3,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 3.3,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 1.7,
"vectorString": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T03:15:08.234Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408054 | Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of service",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408054"
},
{
"name": "VDB-408054 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408054/cti"
},
{
"name": "CVE-2026-94137 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-94137"
},
{
"name": "Submit #893882 | Hangzhou Shunwang Technology Co., Ltd. shzh 10.7.2.693 Incorrect Default Permissions",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/893882"
},
{
"tags": [
"related"
],
"url": "https://www.virustotal.com/gui/file/e3b99f727e59aab08862a161df7e3d7790842a76c42184fb4ba267db14eae4fa"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-20T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-20T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-20T21:37:11.000Z",
"value": "VulDB entry last update"
}
],
"title": "Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of service",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-94137",
"datePublished": "2026-09-21T03:15:08.234Z",
"dateReserved": "2026-09-20T19:31:12.060Z",
"dateUpdated": "2026-09-24T13:14:39.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94094 (GCVE-0-2026-94094)
Vulnerability from cvelistv5 – Published: 2026-09-20 23:00 – Updated: 2026-09-22 15:41- CWE-404 - Denial of Service
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408023 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408023/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-94094 | third-party-advisory |
| https://vuldb.com/submit/882009 | third-party-advisory |
| https://github.com/lche511/cve/tree/main/OpenClaw… | exploit |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94094",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:30:11.647018Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:41:58.927Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*"
],
"modules": [
"Canvas Host Route"
],
"product": "OpenClaw",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "2026.9.0"
},
{
"status": "affected",
"version": "2026.9.1"
},
{
"status": "affected",
"version": "2026.9.2"
},
{
"status": "affected",
"version": "2026.9.3"
},
{
"status": "affected",
"version": "2026.9.4"
},
{
"status": "affected",
"version": "2026.9.5"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "pengguogood (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. Fix suggestion\u0027s \"streaming/size-limit\" was never shipped - latest 2026.9.5 still buffers the whole file via readFile() (src/canvas/serve.runtime.ts:17,114), unlike the sibling WS path which caps at 64KB. The vendor was contacted early about this disclosure."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T23:00:14.987Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408023 | OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408023"
},
{
"name": "VDB-408023 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408023/cti"
},
{
"name": "CVE-2026-94094 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-94094"
},
{
"name": "Submit #882009 | OpenClaw openclaw@2026.6.11 Denial of Service",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/882009"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/lche511/cve/tree/main/OpenClaw_Canvas_Big_GET_DoS_Report"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-20T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-20T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-20T11:12:49.000Z",
"value": "VulDB entry last update"
}
],
"title": "OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-94094",
"datePublished": "2026-09-20T23:00:14.987Z",
"dateReserved": "2026-09-20T09:07:39.802Z",
"dateUpdated": "2026-09-22T15:41:58.927Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93312 (GCVE-0-2026-93312)
Vulnerability from cvelistv5 – Published: 2026-09-18 00:45 – Updated: 2026-09-22 18:23 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/406610 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/406610/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93312 | third-party-advisory |
| https://vuldb.com/submit/942345 | third-party-advisory |
| https://gitlab.freedesktop.org/poppler/poppler/-/… | related |
| https://gitlab.freedesktop.org/poppler/poppler/-/… | patch |
| https://github.com/r1ck9-2q/cve_summit/blob/main/… | exploit |
| https://gitlab.freedesktop.org/poppler/poppler/-/… | broken-linkpatch |
| Vendor | Product | Version | |
|---|---|---|---|
| Freedesktop | Poppler |
Affected:
26.07.0
Unaffected: 26.08.0 cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93312",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T18:22:51.076168Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T18:23:02.769Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/942345"
},
{
"tags": [
"exploit"
],
"url": "https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*"
],
"product": "Poppler",
"vendor": "Freedesktop",
"versions": [
{
"status": "affected",
"version": "26.07.0"
},
{
"status": "unaffected",
"version": "26.08.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "r1ck99 (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "NULL Pointer Dereference",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T00:45:12.489Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-406610 | Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/406610"
},
{
"name": "VDB-406610 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/406610/cti"
},
{
"name": "CVE-2026-93312 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93312"
},
{
"name": "Submit #942345 | freedesktop.org Poppler 26.07.0 NULL Pointer Dereference",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/942345"
},
{
"tags": [
"related"
],
"url": "https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759"
},
{
"tags": [
"patch"
],
"url": "https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/r1ck9-2q/cve_summit/blob/main/Null-pointer-offset-undefined-behavior-in-JBIG2Stream-rewind-JBIG2Stream.cc-1229.md"
},
{
"tags": [
"broken-link",
"patch"
],
"url": "https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-17T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-17T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-17T19:18:24.000Z",
"value": "VulDB entry last update"
}
],
"title": "Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93312",
"datePublished": "2026-09-18T00:45:12.489Z",
"dateReserved": "2026-09-17T17:13:08.412Z",
"dateUpdated": "2026-09-22T18:23:02.769Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92881 (GCVE-0-2026-92881)
Vulnerability from cvelistv5 – Published: 2026-09-17 15:30 – Updated: 2026-09-23 16:19 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/406347 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/406347/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-92881 | third-party-advisory |
| https://vuldb.com/submit/942165 | third-party-advisory |
| https://github.com/vgmstream/vgmstream/issues/1996 | issue-tracking |
| https://github.com/vgmstream/vgmstream/pull/2008 | issue-trackingpatch |
| https://github.com/vgmstream/vgmstream/commit/ae3… | patch |
| https://github.com/vgmstream/vgmstream/ | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92881",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T16:19:23.155701Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T16:19:30.188Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*"
],
"modules": [
"AWB parser"
],
"product": "vgmstream",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ni-liao (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be executed remotely. The name of the patch is ae37662ad626254ddd96ad69ac263792d7a92024. A patch should be applied to remediate this issue."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-369",
"description": "Divide By Zero",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T15:30:13.793Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-406347 | vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/406347"
},
{
"name": "VDB-406347 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/406347/cti"
},
{
"name": "CVE-2026-92881 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-92881"
},
{
"name": "Submit #942165 | vgmstream r2117 Divide by Zero",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/942165"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/vgmstream/vgmstream/issues/1996"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/vgmstream/vgmstream/pull/2008"
},
{
"tags": [
"patch"
],
"url": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024"
},
{
"tags": [
"product"
],
"url": "https://github.com/vgmstream/vgmstream/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-17T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-17T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-17T10:23:03.000Z",
"value": "VulDB entry last update"
}
],
"title": "vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-92881",
"datePublished": "2026-09-17T15:30:13.793Z",
"dateReserved": "2026-09-17T08:17:41.156Z",
"dateUpdated": "2026-09-23T16:19:30.188Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation MIT-3
Strategy: Language Selection
- Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
- For example, languages such as Java, Ruby, and Lisp perform automatic garbage collection that releases memory for objects that have been deallocated.
Mitigation
It is good practice to be responsible for freeing all resources you allocate and to be consistent with how and where you free memory in a function. If you allocate memory that you intend to free upon completion of the function, you must be sure to free the memory at all exit points for that function including error conditions.
Mitigation
Memory should be allocated/freed using matching functions such as malloc/free, new/delete, and new[]/delete[].
Mitigation
When releasing a complex object or structure, ensure that you properly dispose of all of its member components, not just the object itself.
CAPEC-125: Flooding
An adversary consumes the resources of a target by rapidly engaging in a large number of interactions with the target. This type of attack generally exposes a weakness in rate limiting or flow. When successful this attack prevents legitimate users from accessing the service and can cause the target to crash. This attack differs from resource depletion through leaks or allocations in that the latter attacks do not rely on the volume of requests made to the target but instead focus on manipulation of the target's operations. The key factor in a flooding attack is the number of requests the adversary can make in a given period of time. The greater this number, the more likely an attack is to succeed against a given target.
CAPEC-130: Excessive Allocation
An adversary causes the target to allocate excessive resources to servicing the attackers' request, thereby reducing the resources available for legitimate services and degrading or denying services. Usually, this attack focuses on memory allocation, but any finite resource on the target could be the attacked, including bandwidth, processing cycles, or other resources. This attack does not attempt to force this allocation through a large number of requests (that would be Resource Depletion through Flooding) but instead uses one or a small number of requests that are carefully formatted to force the target to allocate excessive resources to service this request(s). Often this attack takes advantage of a bug in the target to cause the target to allocate resources vastly beyond what would be needed for a normal request.
CAPEC-131: Resource Leak Exposure
An adversary utilizes a resource leak on the target to deplete the quantity of the resource available to service legitimate requests.
CAPEC-494: TCP Fragmentation
An adversary may execute a TCP Fragmentation attack against a target with the intention of avoiding filtering rules of network controls, by attempting to fragment the TCP packet such that the headers flag field is pushed into the second fragment which typically is not filtered.
CAPEC-495: UDP Fragmentation
An attacker may execute a UDP Fragmentation attack against a target server in an attempt to consume resources such as bandwidth and CPU. IP fragmentation occurs when an IP datagram is larger than the MTU of the route the datagram has to traverse. Typically the attacker will use large UDP packets over 1500 bytes of data which forces fragmentation as ethernet MTU is 1500 bytes. This attack is a variation on a typical UDP flood but it enables more network bandwidth to be consumed with fewer packets. Additionally it has the potential to consume server CPU resources and fill memory buffers associated with the processing and reassembling of fragmented packets.
CAPEC-496: ICMP Fragmentation
An attacker may execute a ICMP Fragmentation attack against a target with the intention of consuming resources or causing a crash. The attacker crafts a large number of identical fragmented IP packets containing a portion of a fragmented ICMP message. The attacker these sends these messages to a target host which causes the host to become non-responsive. Another vector may be sending a fragmented ICMP message to a target host with incorrect sizes in the header which causes the host to hang.
CAPEC-666: BlueSmacking
An adversary uses Bluetooth flooding to transfer large packets to Bluetooth enabled devices over the L2CAP protocol with the goal of creating a DoS. This attack must be carried out within close proximity to a Bluetooth enabled device.