← Back
CWE-400

3,105 CVEs • Abstraction: Class • Likelihood of Exploit: High

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

JSON object

Loading...

CVEs (3,105)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Htmlunit
1Htmlunit
Nov 21, 2024
May 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a...Show more
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack.This issue affects htmlunit before 2.70.0. Show less
1Briarproject
1Briar
Jan 16, 2025
May 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact.
1Cybozu
1Garoon
Jan 28, 2025
May 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.
1Bitcoin
1Bitcoin Core
Jan 28, 2025
May 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 20...Show more
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.Show less
1Westerndigital
4My Cloud Home Duo Firmware
My Cloud Home FirmwareMy Cloud Os 5+1 more
Nov 21, 2024
May 18, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was...Show more
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue requires the attacker to already have root privileges in order to exploit this vulnerability.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202. Show less
2Libreswan
Redhat
5Enterprise Linux
Enterprise Linux EusEnterprise Linux Server Aus+2 more
Jan 22, 2025
May 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero re...Show more
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.Show less
1Reactphp
1Http
Nov 21, 2024
May 17, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when...Show more
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when processing large HTTP request bodies. This vulnerability has little to no impact on the default configuration, but can be exploited when explicitly using the RequestBodyBufferMiddleware with very large settings. This might lead to consuming large amounts of CPU time for processing requests and significantly delay or slow down the processing of legitimate user requests. This issue has been addressed in release 1.9.0. Users are advised to upgrade. Users unable to upgrade may keep the request body limited using RequestBodyBufferMiddleware with a sensible value which should mitigate the issue. An infrastructure or DevOps workaround could be to place a reverse proxy in front of the ReactPHP HTTP server to filter out any excessive HTTP request bodies. Show less
1Google
1Android
Jan 24, 2025
May 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed...Show more
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258422365Show less
1Google
1Android
Jan 24, 2025
May 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges ne...Show more
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-250576066Show less
2Opcfoundation
Prosysopc
4Ua Historian
Ua Java LegacyUa Modbus Server+1 more
Nov 21, 2024
May 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.
1Sick
7Ftmg Esd15axx Firmware
Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 more
Jun 1, 2026
May 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by in...Show more
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.Show less
1Sick
7Ftmg Esd15axx Firmware
Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 more
Jun 1, 2026
May 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the we...Show more
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.Show less
1Rocketchat
1Rocket.chat
Jan 27, 2025
May 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the serv...Show more
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.Show less
1Westerndigital
3My Cloud Home Duo Firmware
My Cloud Home FirmwareSandisk Ibi Firmware
Nov 21, 2024
May 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issu...Show more
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. Show less
1Protocol
1Boxo
Nov 21, 2024
May 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is able allocate arbitrary many bytes in the Bitswap server, those allocati...Show more
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is able allocate arbitrary many bytes in the Bitswap server, those allocations are lasting even if the connection is closed. This affects users accepting untrusted connections with the Bitswap server and also affects users using the old API stubs at `github.com/ipfs/go-libipfs/bitswap` because users then transitively import `github.com/ipfs/go-libipfs/bitswap/server`. Boxo versions 0.6.0 and 0.4.1 contain a patch for this issue. As a workaround, those who are using the stub object at `github.com/ipfs/go-libipfs/bitswap` not taking advantage of the features provided by the server can refactor their code to use the new split API that will allow them to run in a client only mode: `github.com/ipfs/go-libipfs/bitswap/client`.Show less
1Intel
1Unite
Nov 21, 2024
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentially enable denial of service via local access.
1Intel
1Smart Campus
Nov 21, 2024
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potentially enable denial of service via local access.
1Intel
1Connect M
Nov 21, 2024
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable denial of service via local access.
1Octopus
1Octopus Server
Jan 28, 2025
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
May 19, 2026
May 9, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Microsoft Access Denial of Service Vulnerability