CWE-1049
Excessive Data Query Operations in a Large Data Table
Description
The product performs a data query with a large number of joins and sub-queries on a large data table.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-0190 | Hig | 0.49 | 7.5 | 0.01 | Mar 20, 2025 | In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an extended period while processing… | ||
| CVE-2019-8460 | Hig | 0.42 | 7.5 | 0.02 | Aug 26, 2019 | OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service. | ||
| CVE-2023-5192 | Med | 0.35 | 6.5 | 0.01 | Sep 27, 2023 | Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0. |
- risk 0.49cvss 7.5epss 0.01
In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an extended period while processing…
- risk 0.42cvss 7.5epss 0.02
OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.
- risk 0.35cvss 6.5epss 0.01
Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.