Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CWE-399 (资源管理错误) — Vulnerability Class 158

158 vulnerabilities classified as CWE-399 (资源管理错误). AI Chinese analysis included.

This page provides a comprehensive aggregation of vulnerabilities associated with the weakness type CWE-399, often referred to as Performance Optimization Issues. It systematically collects and organizes security data affecting various vendors, products, and software categories where inefficient code or resource management leads to operational degradation or denial of service conditions. The dataset covers historical records spanning several years, capturing the evolution of these performance-related flaws as they have been identified, disclosed, and patched across the software ecosystem. By centralizing this information, the page serves as a critical resource for security professionals, developers, and system administrators who need to assess the impact of suboptimal performance configurations on overall system stability. Visitors can track vendor advisories related to performance bottlenecks, understand the broader context of the CWE-399 weakness class within common programming paradigms, and look up specific products to review their vulnerability history regarding resource exhaustion, memory leaks, or excessive CPU usage. This structured approach allows users to identify patterns in how performance issues are reported and resolved over time. The content is intended for technical analysis rather than general awareness, focusing on the mechanistic aspects of how poor optimization results in exploitable conditions. It does not provide mitigation strategies directly but offers the foundational data necessary for deeper investigation into source code efficiency and architectural design choices. Users are encouraged to cross-reference this data with official vendor statements and detailed technical disclosures to gain a complete understanding of the risks involved.

CVE IDTitleCVSSSeverityPublished
CVE-2019-1587 Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Filter Query Information Disclosure Vulnerability — Cisco Application Policy Infrastructure Controller (APIC) 4.3 -2019-05-03
CVE-2019-1800 Cisco Wireless LAN Controller Software IAPP Message Handling Denial of Service Vulnerabilities — Cisco Wireless LAN Controller (WLC) 6.5 -2019-04-18
CVE-2019-1796 Cisco Wireless LAN Controller Software IAPP Message Handling Denial of Service Vulnerabilities — Cisco Wireless LAN Controller (WLC) 6.5 -2019-04-18
CVE-2019-1799 Cisco Wireless LAN Controller Software IAPP Message Handling Denial of Service Vulnerabilities — Cisco Wireless LAN Controller (WLC) 6.5 -2019-04-18
CVE-2019-1718 Cisco Identity Services Engine SSL Renegotiation Denial of Service Vulnerability — Cisco Identity Services Engine Software 7.5 -2019-04-17
CVE-2018-0389 Cisco Small Business SPA514G IP Phones SIP Denial of Service Vulnerability — Cisco Small Business SPA500 Series IP Phones 7.5 -2019-03-13
CVE-2019-1599 Cisco NX-OS Software Netstack Denial of Service Vulnerability — Nexus 1000V Switch for Microsoft Hyper-V 8.6 -2019-03-07
CVE-2019-1700 Cisco Firepower 9000 Series Firepower 2-Port 100G Double-Width Network Module Queue Wedge Denial of Service Vulnerability — Cisco Firepower Extensible Operating System (FXOS) 6.1 -2019-02-21
CVE-2019-1684 Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability — Cisco IP Phone 8800 Series Software 6.5 -2019-02-21
CVE-2018-15617 Communication Manager Denial of Service — Communication Manager 7.5 -2019-02-01
CVE-2018-15458 Cisco Firepower Management Center Disk Utilization Denial of Service Vulnerability — Cisco Firepower Management Center 7.5 -2019-01-10
CVE-2018-0443 Cisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Denial of Service Vulnerability — Cisco Wireless LAN Controller (WLC) 7.5 -2018-10-17
CVE-2018-0421 Cisco Prime Access Registrar Denial of Service Vulnerability — Cisco Prime Access Registrar 7.5 -2018-10-05
CVE-2018-0457 Cisco Webex Player WRF Files Denial of Service Vulnerability — Cisco WebEx WRF Player 5.5 -2018-10-05
CVE-2018-0466 Cisco IOS and IOS XE Software OSPFv3 Denial of Service Vulnerability — Cisco IOS Software 6.5 -2018-10-05
CVE-2018-0470 Cisco IOS XE Software HTTP Denial of Service Vulnerability — Cisco IOS XE Software 8.6 -2018-10-05
CVE-2018-0473 Cisco IOS Software Precision Time Protocol Denial of Service Vulnerability — Cisco IOS Software 8.6 -2018-10-05
CVE-2018-0476 Cisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service Vulnerability — Cisco IOS XE Software 5.9 -2018-10-05
CVE-2018-15373 Cisco IOS and IOS XE Software Cisco Discovery Protocol Denial of Service Vulnerability — Cisco IOS Software 7.4 -2018-10-05
CVE-2018-15390 Cisco Firepower Threat Defense Software FTP Inspection Denial of Service Vulnerability — Cisco Firepower Threat Defense Software 6.8 -2018-10-05
CVE-2018-15391 Cisco Remote PHY IPv4 Fragment Denial of Service Vulnerability — Cisco Remote PHY 7.5 -2018-10-05
CVE-2018-15392 Cisco Industrial Network Director DHCP Request Processing Denial of Service Vulnerability — Cisco Industrial Network Director 4.3 -2018-10-05
CVE-2018-15396 Cisco Unity Connection File Upload Denial of Service Vulnerability — Cisco Unity Connection 4.9 -2018-10-05
CVE-2018-15404 Cisco Integrated Management Controller Supervisor and Cisco UCS Director System Resources Denial of Service Vulnerability — Cisco Unified Computing System Director 6.5 -2018-10-05
CVE-2018-0397 Cisco AMP for Endpoints Mac Connector Software for macOS 资源管理错误漏洞 — Cisco AMP for Endpoints Mac Connector unknown 7.5 -2018-08-01
CVE-2018-0380 Cisco Webex Network Recording Player 资源管理错误漏洞 — Cisco Webex Network Recording Players unknown 6.3 -2018-07-18
CVE-2018-0370 Cisco Firepower System Software检测引擎资源管理错误漏洞 — Cisco Firepower unknown 7.5 -2018-07-16
CVE-2018-0385 Cisco Firepower System Software检测引擎安全漏洞 — Cisco Firepower unknown 7.5 -2018-07-16
CVE-2018-4851 Siemens SICLOCK TC100和SICLOCK TC400 安全漏洞 — SICLOCK TC100, SICLOCK TC400 7.5 -2018-07-03
CVE-2018-0310 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件资源管理错误漏洞 — Cisco FXOS and NX-OS unknown 9.1 -2018-06-21

Vulnerabilities classified as CWE-399 (资源管理错误) represent 158 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.