← Back
CWE-400

3,101 CVEs • Abstraction: Class • Likelihood of Exploit: High

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

JSON object

Loading...

CVEs (3,101)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Mattermost Server
Nov 21, 2024
Jul 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
1Dotnetfoundation
1C# Language Server Protocol
Nov 21, 2024
Jul 17, 2023
N/A· v4
7.5 HIGH· v3
2.7 LOW· v2
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serializati...Show more
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The manipulation leads to resource consumption. Upgrading to version 0.19.7 is able to address this issue. The patch is identified as 7fd2219f194a9ef2a8901bb131c5fa12272305ce. It is recommended to upgrade the affected component. VDB-234238 is the identifier assigned to this vulnerability.Show less
1Discourse
1Discourse
Nov 21, 2024
Jul 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advi...Show more
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
2Envoyproxy
Nghttp2
2Envoy
Nghttp2
Nov 21, 2024
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an up...Show more
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if connection is already marked for not sending more requests due to `GOAWAY` frame. The clean-up code is right after the return statement, causing memory leak. Denial of service through memory exhaustion. This vulnerability was patched in versions(s) 1.26.3, 1.25.8, 1.24.9, 1.23.11.Show less
1Github
1Cmark Gfm
Nov 21, 2024
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource...Show more
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12. Show less
1Multiversx
1Mx Chain Go
Nov 21, 2024
Jul 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's...Show more
mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's sender account nonce. This could have contributed to a limited DoS attack on a targeted account. The fix is a breaking change so a new flag `RelayedNonceFixEnableEpoch` was needed. This was a strict processing issue while validating blocks on a chain. This vulnerability has been patched in version 1.4.17.Show less
1Honeywell
1C300 Firmware
Nov 21, 2024
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security...Show more
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning. Show less
1Zabbix
1Zabbix
Nov 3, 2025
Jul 13, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles...Show more
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to perform tasks that require more control over the system. The security risk is limited because not all users have this level of access. Show less
1Google
1Android
Nov 21, 2024
Jul 13, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...Show more
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Show less
1Mikrotik
1Routeros
Nov 21, 2024
Jul 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
1Microsoft
10Windows 10 1507
Windows 10 1607Windows 10 1809+7 more
Nov 21, 2024
Jul 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Windows CryptoAPI Denial of Service Vulnerability
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Nov 21, 2024
Jul 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows Authentication Denial of Service Vulnerability
1Microsoft
3Windows 11 21h2
Windows 11 22h2Windows Server 2022
Nov 21, 2024
Jul 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
HTTP.sys Denial of Service Vulnerability
1Linux
1Linux Kernel
Mar 6, 2025
Jul 11, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to cra...Show more
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.Show less
1Siemens
6Simatic Mv540 H Firmware
Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 more
Nov 21, 2024
Jul 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (...Show more
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted Ethernet frames sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.Show less
1Siemens
6Simatic Mv540 H Firmware
Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 more
Nov 21, 2024
Jul 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (...Show more
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted IP packets sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.Show less
1Anydesk
1Anydesk
Nov 21, 2024
Jul 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
AnyDesk 7.0.8 allows remote Denial of Service.
3Fedoraproject
LinuxRedhat
3Enterprise Linux
FedoraLinux Kernel
Nov 21, 2024
Jun 30, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth...Show more
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.Show less
1Google
1Android
Dec 5, 2024
Jun 28, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local denial of service with System execution privileges needed. User interaction is not...Show more
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222287335Show less
1Diagrams
1Drawio
Nov 21, 2024
Jun 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.