About “Denial of Service (DoS)”

A curated feed of “Denial of Service (DoS)”-related CVEs appears below. We currently track 39647 CVEs for this tag (all time). In the last 365 days, 3219 were published. Average CVSS is 6.6 (all time; 6.6 over 365d), and 47% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-400 - Uncontrolled Resource Consumption, CWE-770 - Allocation of Resources Without Limits or Throttling, CWE-476 - NULL Pointer Dereference.

In our taxonomy this topic maps to a LOW impact class. Vendor advisories and release notes are key. Verify compatibility matrices, prefer supported long term versions, and stage rollouts with monitoring. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
1997-12-16
Medium

CVE-1999-0015

Teardrop IP denial of service.

Medium

CVE-1999-0104

A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.

1997-12-01
Medium

CVE-1999-0016

Land IP denial of service.

Medium

CVE-1999-0193

Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.

1997-11-01
Medium

CVE-1999-0216

Denial of service of inetd on Linux through SYN and RST packets.

1997-10-24
Medium

CVE-1999-1131

Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.

Medium

CVE-1999-1261

Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.

1997-10-01
Medium

CVE-1999-0272

Denial of service in Slmail v2.5 through the POP3 port.

Medium

CVE-1999-0294

All records in a WINS database can be deleted through SNMP for a denial of service.

Medium

CVE-1999-1213

Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.

1997-09-19
Critical

CVE-1999-0667

The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.

High

CVE-1999-0956

The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.

1997-09-15
Low

CVE-1999-1214

The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain…

1997-09-12
Medium

CVE-1999-0079

Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.

1997-08-01
Medium

CVE-1999-0566

An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.

1997-07-23
Medium

CVE-1999-1068

Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.

1997-07-10
Medium

CVE-1999-1463

Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which th…

1997-07-01
Medium

CVE-1999-0153

Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.

Medium

CVE-1999-0195

Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.

High

CVE-1999-0219

Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.

Critical

CVE-1999-0250

Denial of service in Qmail through long SMTP commands.

1997-06-26
Low

CVE-1999-1423

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

1997-06-10
Medium

CVE-1999-0275

Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.

1997-06-01
Low

CVE-1999-0144

Denial of service in Qmail by specifying a large number of recipients with the RCPT command.

Medium

CVE-1999-0227

Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.

Medium

CVE-1999-0281

Denial of service in IIS using long URLs.

1997-05-19
Low

CVE-1999-1449

SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.

1997-04-02
Medium

CVE-1999-1387

Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the…

1997-04-01
Medium

CVE-1999-0292

Denial of service through Winpopup using large user names.

1997-03-05
Low

CVE-1999-1408

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the sock…

1997-02-07
Medium

CVE-1999-0228

Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.

1997-01-01
Low

CVE-1999-0171

Denial of service in syslog by sending it a large number of superfluous messages.

Medium

CVE-1999-0251

Denial of service in talk program allows remote attackers to disrupt a user's display.

Medium

CVE-1999-0274

Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.

Medium

CVE-1999-0345

Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

1996-12-24
Low

CVE-1999-1251

Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.

1996-12-18
Medium

CVE-1999-0128

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

1996-09-19
Medium

CVE-1999-0116

Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.

1996-09-11
High

CVE-1999-0131

Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.

1996-06-07
Low

CVE-1999-1205

nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.

1996-05-17
Low

CVE-1999-1314

Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_unio…

1994-12-19
Medium

CVE-2000-0508

rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.

1994-01-01
Medium

CVE-1999-0181

The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.

1993-09-17
Critical

CVE-1999-1138

SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those…

1993-05-24
Medium

CVE-1999-1162

Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.

1992-07-21
Critical

CVE-1999-0214

Denial of service by sending forged ICMP unreachable packets.

High

CVE-1999-1396

Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).