CWE-400
3,101 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,101)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
|
1Dotnetfoundation 1C# Language Server Protocol Nov 21, 2024 Jul 17, 2023 N/A· v4 7.5 HIGH· v3 2.7 LOW· v2 A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serializati...Show more |
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advi...Show more |
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an up...Show more |
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource...Show more |
mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's...Show more |
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security...Show more |
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles...Show more |
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...Show more |
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. |
1Microsoft 10Windows 10 1507 Windows 10 1607Windows 10 1809+7 moreNov 21, 2024 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows CryptoAPI Denial of Service Vulnerability |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreNov 21, 2024 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows Authentication Denial of Service Vulnerability |
1Microsoft 3Windows 11 21h2 Windows 11 22h2Windows Server 2022Nov 21, 2024 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP.sys Denial of Service Vulnerability |
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to cra...Show more |
1Siemens 6Simatic Mv540 H Firmware Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 moreNov 21, 2024 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (...Show more |
1Siemens 6Simatic Mv540 H Firmware Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 moreNov 21, 2024 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (...Show more |
AnyDesk 7.0.8 allows remote Denial of Service. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelNov 21, 2024 Jun 30, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth...Show more |
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local denial of service with System execution privileges needed. User interaction is not...Show more |
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. |