CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreNov 21, 2024 Jul 9, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreNov 21, 2024 Jul 9, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreNov 21, 2024 Jul 9, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreNov 21, 2024 Jul 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows Line Printer Daemon Service Denial of Service Vulnerability |
1Microsoft 5Windows Server 2012 Windows Server 2016Windows Server 2019+2 moreNov 21, 2024 Jul 9, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreNov 21, 2024 Jul 9, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Windows iSCSI Service Denial of Service Vulnerability |
.NET and Visual Studio Denial of Service Vulnerability |
A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file. |
Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplication in GraphQL is a type of attack where an attacker exploits the flexibility of GraphQL...Show more |
In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon and hwmon drvdata (on which hwmon depends) are device managed resources, the expectation, on device un...Show more |
The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sen...Show more |
The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regula...Show more |
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This...Show more |
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack. |
Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the applicati...Show more |
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consu...Show more |
2Jungo Mitsubishielectric35Cpu Module Logging Configuration Tool Cw ConfiguratorData Transfer+32 moreNov 21, 2024 Jul 2, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). |
2Jungo Mitsubishielectric35Cpu Module Logging Configuration Tool Cw ConfiguratorData Transfer+32 moreMar 18, 2025 Jul 2, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error. |
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which...Show more |
An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a deni...Show more |