CWE-400
3,106 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,106)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above `0.2.5`. There are currently no known wor...Show more |
3Dpdk OpenvswitchRedhat3Data Plane Development Kit Openshift Container PlatformOpenvswitchNov 21, 2024 Aug 29, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by...Show more |
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privil...Show more |
5Debian FedoraprojectIbm+2 more23Build Of Quarkus Codeready Linux BuilderDebian Linux+20 moreNov 3, 2025 Aug 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. |
A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially...Show more |
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereferenc...Show more |
2Apache Redhat3Activemq Artemis Amq BrokerArtemisJun 15, 2026 Aug 24, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the br...Show more |
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription paramet...Show more |
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress. |
A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from th...Show more |
2Debian Linux2Debian Linux Linux KernelNov 21, 2024 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to...Show more |
1Redhat 7Fuse Integration Camel KIntegration Camel Quarkus+4 moreNov 21, 2024 Aug 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is a...Show more |
3Fedoraproject RedhatSamba3Fedora SambaStorageAug 21, 2025 Aug 23, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 MaxQueryDuration not honoured in Samba AD DC LDAP |
A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulner...Show more |
PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp. |
2Fedoraproject Varnish Cache Project2Fedora Varnish CacheOct 20, 2025 Aug 11, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backe...Show more |
1Microsoft 1Azure Site Recovery Vmware To Azure May 29, 2025 Aug 9, 2022 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Azure Site Recovery Denial of Service Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreMay 29, 2025 Aug 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 4, 2025 Aug 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability |
1F Secure 8Atlant Cloud Protection For SalesforceElements Collaboration Protection+5 moreJun 2, 2026 Aug 5, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be trigge...Show more |