CWE-400
3,106 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,106)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 May 5, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters are enabled and a virtual server is configured with the type set to Rej...Show more |
1F5 1Big Ip Access Policy Manager Nov 21, 2024 May 5, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when APM is configured on...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 May 5, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when a DNS listener is configured on a virtual server with DNS qu...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreNov 21, 2024 May 5, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at least guest role privileges can cause processing delays to iControl REST requests vi...Show more |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreNov 21, 2024 May 4, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7. |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseNov 21, 2024 May 3, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service c...Show more |
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulner...Show more |
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources. |
1Http Swagger Project 1Http Swagger Nov 21, 2024 Apr 18, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a denial of service attack consisting of mem...Show more |
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability...Show more |
2Debian Digium2Asterisk Debian LinuxNov 21, 2024 Apr 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Re...Show more |
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent from the local broadcast domain, may allow an unauthenticated network-a...Show more |
Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial of service attack via a crafted object causing a hash collision. This collision causes the server to...Show more |
1Mattermost 1Mattermost Server Nov 21, 2024 Apr 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files. |
1Fernhillsoftware 1Scada Server Nov 21, 2024 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. |
1Siemens 3Simatic Pcs Neo SinetplanTotally Integrated Automation PortalNov 21, 2024 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process speci...Show more |
1Siemens 12Simatic Cfu Diq Firmware Simatic Cfu Pa FirmwareSimatic S7 1500 Cpu Firmware+9 moreNov 21, 2024 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to c...Show more |
2Nekohtml Project Oracle2Nekohtml Weblogic ServerNov 21, 2024 Apr 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreNov 21, 2024 Apr 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents...Show more |
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab |