CWE-400
3,621 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,621)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import...Show more |
3Debian FedoraprojectOpenidc3Debian Linux FedoraMod Auth OpenidcJun 17, 2026 Feb 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validatio...Show more |
1Microsoft 2Asp.net Core Visual Studio 2022Aug 10, 2026 Feb 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Denial of Service Vulnerability |
1Microsoft 3Windows 11 22h2 Windows 11 23h2Windows Server 2022 23h2Jun 17, 2026 Feb 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows DNS Client Denial of Service Vulnerability |
1Hima 13F Com 01 Firmware F Cpu 01 FirmwareF30 03x Yy (com) Firmware+10 moreJun 17, 2026 Feb 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port. |
Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.
|
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to...Show more |
3Fedoraproject LatchsetRedhat6Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+3 moreJun 17, 2026 Feb 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Feb 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Feb 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Feb 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV u...Show more |
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it,...Show more |
Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such match...Show more |
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent cus...Show more |
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function. |
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function. |
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and...Show more |
The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972. |
IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 255827. |
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single...Show more |