CWE-400
3,106 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,106)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO addre...Show more |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreMay 27, 2026 Sep 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Core and Visual Studio Denial of Service Vulnerability |
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device t...Show more |
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM...Show more |
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-node, an attacker can max out the number of client connections allowed by...Show more |
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations,...Show more |
JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto in Node.js, Browser, Cloudflare Workers, Electron, and Deno. The PBKDF2-based JWE key management alg...Show more |
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is t...Show more |
Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow each other's paynym. Then, the victim must try to collaborate with the attacker for a Stonewallx2 tr...Show more |
Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shells `Bash` and `Dash`, or any not-official...Show more |
2Debian Libvncserver Project2Debian Linux LibvncserverNov 21, 2024 Sep 2, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). |
1Qualcomm 17Apq8096au Firmware Qam8295p FirmwareQca6564a Firmware+14 moreNov 21, 2024 Sep 2, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto |
An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments extension could cause a site to become unavailable due to insufficient validation when certain actions...Show more |
2Netapp Redhat9Active Iq Unified Manager Cloud Secure AgentIntegration Camel K+6 moreNov 21, 2024 Sep 1, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. |
1Redhat 1Openshift Container Platform Nov 21, 2024 Sep 1, 2022 N/A· v4 6.3 MEDIUM· v3 N/A· v2 In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry ca...Show more |
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files. |
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input to functions in the _strvals_ package that can cause an out of memory p...Show more |
1Automationdirect 9D0 06aa Firmware D0 06ar FirmwareD0 06da Firmware+6 moreNov 21, 2024 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affect...Show more |
A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gig...Show more |
2Netapp Redhat10Active Iq Unified Manager Build Of QuarkusCloud Secure Agent+7 moreNov 21, 2024 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-...Show more |