CWE-400
3,105 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,105)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a...Show more |
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact. |
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition. |
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 20...Show more |
1Westerndigital 4My Cloud Home Duo Firmware My Cloud Home FirmwareMy Cloud Os 5+1 moreNov 21, 2024 May 18, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was...Show more |
2Libreswan Redhat5Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+2 moreJan 22, 2025 May 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero re...Show more |
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when...Show more |
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed...Show more |
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges ne...Show more |
2Opcfoundation Prosysopc4Ua Historian Ua Java LegacyUa Modbus Server+1 moreNov 21, 2024 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications. |
1Sick 7Ftmg Esd15axx Firmware Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 moreJun 1, 2026 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by in...Show more |
1Sick 7Ftmg Esd15axx Firmware Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 moreJun 1, 2026 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the we...Show more |
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the serv...Show more |
1Westerndigital 3My Cloud Home Duo Firmware My Cloud Home FirmwareSandisk Ibi FirmwareNov 21, 2024 May 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issu...Show more |
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is able allocate arbitrary many bytes in the Bitswap server, those allocati...Show more |
Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentially enable denial of service via local access. |
Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potentially enable denial of service via local access. |
Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable denial of service via local access. |
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelMay 19, 2026 May 9, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 Microsoft Access Denial of Service Vulnerability |