CWE-400
3,616 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,616)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Withsecure 7Atlant Client SecurityElements Endpoint Protection+4 moreJun 17, 2026 Sep 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Serve...Show more |
1Withsecure 7Atlant Client SecurityElements Endpoint Protection+4 moreJun 17, 2026 Sep 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 1...Show more |
1Withsecure 7Atlant Client SecurityElements Endpoint Protection+4 moreJun 17, 2026 Sep 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Securi...Show more |
1Withsecure 7Atlant Client SecurityElements Endpoint Protection+4 moreJun 17, 2026 Sep 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 1...Show more |
Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows...Show more |
A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service. |
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very sl...Show more |
A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service. |
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service. |
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0. Users are recommended to upgrade...Show more |
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStora...Show more |
1Microsoft 4Windows Server 2012 Windows Server 2016Windows Server 2019+1 moreJun 17, 2026 Sep 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 DHCP Server Service Denial of Service Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Sep 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows TCP/IP Denial of Service Vulnerability |
.NET Core and Visual Studio Denial of Service Vulnerability |
Cyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages "PNTMEDIDAS", "PEDIR", "HAYDISCOA" or "SPOOLER". A complete denial of service can be...Show more |
Buffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could cause a Buffer Overflow when the adminitrator tries to accept or delete the prin...Show more |
Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, c...Show more |
1Hichip 1Shenzhen Hichip Vision Technology Firmware Jun 17, 2026 Sep 11, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Shenzhen Hichip Vision Technology IP Camera Firmware V11.4.8.1.1-20170926 has a denial of service vulnerability through sending a crafted multicast message in a local network. |
An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication. |
Processing an incomplete post-handshake message for a QUIC connection can cause a panic. |