← Back
CWE-400

3,099 CVEs • Abstraction: Class • Likelihood of Exploit: High

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

JSON object

Loading...

CVEs (3,099)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Mattermost
Nov 21, 2024
Oct 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular...Show more
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel.  Show less
1Ibm
1Security Verify Privilege On Premises
Nov 21, 2024
Oct 17, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IBM X-Force ID: 240634.
1Discourse
1Discourse
Nov 21, 2024
Oct 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched...Show more
Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. It is possible to temporarily work around this problem by reducing the `client_max_body_size nginx directive`. `client_max_body_size` will limit the size of uploads that can be uploaded directly to the server.Show less
1Nextcloud
1Calendar
Nov 21, 2024
Oct 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provi...Show more
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It is recommended that the Nextcloud Calendar app is upgraded to 4.4.4. The only workaround for users unable to upgrade is to disable the calendar app.Show less
1Silverstripe
1Graphql
Nov 21, 2024
Oct 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a webs...Show more
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. This issue has been addressed in versions 3.8.2, 4.1.3, 4.2.5, 4.3.4, and 5.0.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Gpac
1Gpac
Nov 21, 2024
Oct 16, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
1Ibm
1Security Verify Access Oidc Provider
Nov 21, 2024
Oct 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.
1Adobe
2Commerce
Magento
Nov 21, 2024
Oct 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that could lead in minor appl...Show more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that could lead in minor application denial-of-service. Exploitation of this issue does not require user interaction.Show less
1Juniper
1Junos
Nov 21, 2024
Oct 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite...Show more
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover. This issue affects interfaces with PPPoE configured and tcp-mss enabled. This issue affects Juniper Networks Junos OS * All versions prior to 20.4R3-S7; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3; * 22.3 versions prior to 22.3R2-S2; * 22.4 versions prior to 22.4R2; Show less
1Netapp
1Clustered Data Ontap
Nov 21, 2024
Oct 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service.
1Softether
1Vpn
Nov 21, 2024
Oct 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a seque...Show more
A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.Show less
1Microsoft
5Windows Server 2008
Windows Server 2012Windows Server 2016+2 more
Nov 21, 2024
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
DHCP Server Service Denial of Service Vulnerability
1Microsoft
12Windows 10
Windows 10 1607Windows 10 1809+9 more
Dec 12, 2024
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Dec 12, 2024
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
1Microsoft
4.net
Windows 11 21h2Windows 11 22h2+1 more
Nov 21, 2024
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft QUIC Denial of Service Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Dec 12, 2024
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
3Debian
EclipseJenkins
3Debian Linux
JenkinsJetty
Nov 21, 2024
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK...Show more
Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit. `MetaDataBuilder.java` determines if a header name or value exceeds the size limit, and throws an exception if the limit is exceeded. However, when length is very large and huffman is true, the multiplication by 4 in line 295 will overflow, and length will become negative. `(_size+length)` will now be negative, and the check on line 296 will not be triggered. Furthermore, `MetaDataBuilder.checkSize` allows for user-entered HPACK header value sizes to be negative, potentially leading to a very large buffer allocation later on when the user-entered size is multiplied by 2. This means that if a user provides a negative length value (or, more precisely, a length value which, when multiplied by the 4/3 fudge factor, is negative), and this length value is a very large positive number when multiplied by 2, then the user can cause a very large buffer to be allocated on the server. Users of HTTP/2 can be impacted by a remote denial of service attack. The issue has been fixed in versions 11.0.16, 10.0.16, and 9.4.53. There are no known workarounds.Show less
33Akka
AmazonApache+30 more
165.net
3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 more
May 12, 2026
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
3Fedoraproject
RedhatX.org
3Enterprise Linux
FedoraLibx11
Nov 4, 2025
Oct 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
1Siemens
5Simatic Cp 1604 Firmware
Simatic Cp 1616 FirmwareSimatic Cp 1623 Firmware+2 more
Nov 21, 2024
Oct 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). Affected devices insu...Show more
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). Affected devices insufficiently control continuous mapping of direct memory access (DMA) requests. This could allow local attackers with administrative privileges to cause a denial of service situation on the host. A physical power cycle is required to get the system working again.Show less