← Back
CWE-400

3,099 CVEs • Abstraction: Class • Likelihood of Exploit: High

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

JSON object

Loading...

CVEs (3,099)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Free5gc
1Free5gc
Nov 21, 2024
Nov 16, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.
1Ivanti
1Secure Access Client
Nov 21, 2024
Nov 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of servi...Show more
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.Show less
2Arubanetworks
Hp
2Arubaos
Instantos
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal opera...Show more
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. Show less
2Arubanetworks
Hp
2Arubaos
Instantos
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of...Show more
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point. Show less
1Microsoft
2Asp.net Core
Visual Studio 2022
Nov 21, 2024
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ASP.NET Core Denial of Service Vulnerability
1Intel
1Aptio V Uefi Firmware Integrator Tools
Nov 21, 2024
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
1Microsoft
2Visual Studio 2019
Visual Studio 2022
Nov 21, 2024
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Visual Studio Denial of Service Vulnerability
1Siemens
716ag1206 2bb00 7ac2 Firmware
6ag1206 2bs00 7ac2 Firmware6ag1208 0ba00 7ac2 Firmware+68 more
Nov 21, 2024
Nov 14, 2023
5.1 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device need...Show more
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available again.Show less
1Nirmata
1Kyverno
Nov 21, 2024
Nov 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attac...Show more
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno would fetch attestations. With such a position, the attacker could return a malicious response to Kyverno, when Kyverno would send a request to the registry. The malicious response would cause denial of service of Kyverno, such that other users' admission requests would be blocked from being processed. This is a vulnerability in a new component released in v1.11.0. The only users affected by this are those that have been building Kyverno from source at the main branch which is not encouraged. Users consuming official Kyverno releases are not affected. There are no known cases of this vulnerability being exploited in the wild.Show less
1Ibm
2Aix
Vios
Nov 21, 2024
Nov 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965.
1Perforce
1Helix Core
Nov 21, 2024
Nov 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.  
1Perforce
1Helix Core
Nov 21, 2024
Nov 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. 
1Perforce
1Helix Core
Nov 21, 2024
Nov 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  
1Sigstore
1Cosign
Nov 21, 2024
Nov 7, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high number of attestations a...Show more
Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high number of attestations and/or signatures to Cosign and cause Cosign to enter a long loop resulting in an endless data attack. The root cause is that Cosign loops through all attestations fetched from the remote registry in pkg/cosign.FetchAttestations. The attacker needs to compromise the registry or make a request to a registry they control. When doing so, the attacker must return a high number of attestations in the response to Cosign. The result will be that the attacker can cause Cosign to go into a long or infinite loop that will prevent other users from verifying their data. In Kyvernos case, an attacker whose privileges are limited to making requests to the cluster can make a request with an image reference to their own registry, trigger the infinite loop and deny other users from completing their admission requests. Alternatively, the attacker can obtain control of the registry used by an organization and return a high number of attestations instead the expected number of attestations. The issue can be mitigated rather simply by setting a limit to the limit of attestations that Cosign will loop through. The limit does not need to be high to be within the vast majority of use cases and still prevent the endless data attack. This issue has been patched in version 2.2.1 and users are advised to upgrade.Show less
1Mattermost
1Mattermost
Nov 21, 2024
Nov 6, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
1Tigera
3Calico Cloud
Calico EnterpriseCalico Os
Nov 21, 2024
Nov 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in...Show more
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed inside the main server handle for loop without any timeout allowing an unclean TLS handshake to block the main loop indefinitely while other connections will be idle waiting for that handshake to finish. Show less
2Redhat
Samba
8Enterprise Linux
Enterprise Linux EusEnterprise Linux For Ibm Z Systems+5 more
Nov 21, 2024
Nov 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The...Show more
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task, allowing calls to the "rpcecho" server to be blocked for a specified time, causing service disruptions. This disruption is triggered by a "sleep()" call in the "dcesrv_echo_TestSleep()" function under specific conditions. Authenticated users or attackers can exploit this vulnerability to make calls to the "rpcecho" server, requesting it to block for a specified duration, effectively disrupting most services and leading to a complete denial of service on the AD DC. The DoS affects all other services as "rpcecho" runs in the main RPC task.Show less
2Fedoraproject
Samba
2Fedora
Samba
Nov 21, 2024
Nov 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unr...Show more
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same unix domain sockets. This issue leads to partial query responses from the AD DC, causing issues such as "The procedure number is out of range" when using tools like Active Directory Users. This flaw allows an attacker to disrupt AD DC services.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Nov 2, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be m...Show more
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an extended period of time. As a result users were able to trigger large amount of egress network connections, possibly exhausting network pool resources and lock up legitimate requests. A new mechanism has been introduced to cancel external connections that might access user-controlled endpoints. No publicly available exploits are known. Show less
1Mattermost
1Mattermost Desktop
Nov 21, 2024
Nov 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.