CWE-400
3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,618)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal opera...Show more |
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of...Show more |
1Microsoft 2Asp.net Core Visual Studio 2022Jun 17, 2026 Nov 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 ASP.NET Core Denial of Service Vulnerability |
1Intel 1Aptio V Uefi Firmware Integrator Tools Jun 17, 2026 Nov 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. |
1Microsoft 2Visual Studio 2019 Visual Studio 2022Jun 17, 2026 Nov 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Visual Studio Denial of Service Vulnerability |
1Siemens 716ag1206 2bb00 7ac2 Firmware 6ag1206 2bs00 7ac2 Firmware6ag1208 0ba00 7ac2 Firmware+68 moreJun 17, 2026 Nov 14, 2023 5.1 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device need...Show more |
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attac...Show more |
IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965. |
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.
|
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner.
|
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.
|
Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high number of attestations a...Show more |
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
|
1Tigera 3Calico Cloud Calico EnterpriseCalico OsJun 17, 2026 Nov 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in...Show more |
2Redhat Samba8Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems+5 moreJun 17, 2026 Nov 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The...Show more |
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unr...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Nov 2, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be m...Show more |
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
|
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Nov 1, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulner...Show more |
1Redhat 5Openshift Container Platform For Arm64 Openshift Container Platform For LinuxoneOpenshift Container Platform For Power+2 moreJun 17, 2026 Nov 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products. |