CWE-400
3,106 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,106)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian HaxxNetapp+1 more12Clustered Data Ontap CurlDebian Linux+9 moreMay 27, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS g...Show more |
1Rockwellautomation 9Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5370 Firmware+6 moreNov 21, 2024 Jun 2, 2022 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target d...Show more |
1Nextcloud 1Nextcloud Server Nov 21, 2024 May 31, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app password...Show more |
2Netapp Redhat8Active Iq Unified Manager IntegrationJboss Enterprise Application Platform+5 moreNov 21, 2024 May 24, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability...Show more |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.ragged.constant` does not fully validate the input arguments. This results in a deni...Show more |
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if configured to use high verbosity logging, can be made to crash when handling specially crafted p...Show more |
1Siemens 2Simatic Cp 442 1 Rna Firmware Simatic Cp 443 1 Rna FirmwareNov 21, 2024 May 20, 2022 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affected devices improperly handles excessive ARP broadcast requests. This could al...Show more |
OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources. |
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service. |
1Intel 1Software Guard Extensions May 5, 2025 May 12, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access. |
Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications. |
3Apache DebianOracle3Debian Linux Hospitality Cruise Shipboard Property Management SystemTomcatNov 21, 2024 May 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted...Show more |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreMay 27, 2026 May 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 .NET and Visual Studio Denial of Service Vulnerability |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreMay 27, 2026 May 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 .NET and Visual Studio Denial of Service Vulnerability |
1Siemens 4Desigo Dxr2 Firmware Desigo Pxc3 FirmwareDesigo Pxc4 Firmware+1 moreNov 21, 2024 May 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142....Show more |
TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarou...Show more |
Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the request and response, covering the HTTP method, request URI, host, and opti...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 May 5, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Soft...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 May 5, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have rea...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 May 5, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when a Real Time Streaming Protocol (RTSP) profile is configured on...Show more |