CWE-400
3,105 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,105)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments. |
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes. |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Mar 25, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker...Show more |
4Ckeditor DrupalFedoraproject+1 more9Application Express CkeditorCommerce Merchandising+6 moreNov 21, 2024 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular...Show more |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreNov 21, 2024 Mar 11, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4....Show more |
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specia...Show more |
4Fedoraproject NetappPython+1 more20Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+17 moreNov 3, 2025 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReD...Show more |
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate t...Show more |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreMay 27, 2026 Mar 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 .NET and Visual Studio Denial of Service Vulnerability |
3Debian FedoraprojectRust Lang3Debian Linux FedoraRegexNov 21, 2024 Mar 8, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trust...Show more |
6Canonical FedoraprojectNetapp+3 more17Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+14 moreDec 17, 2025 Mar 4, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU...Show more |
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, whic...Show more |
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting t...Show more |
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and...Show more |
2Fedoraproject Radare2Fedora Radare2Nov 21, 2024 Feb 24, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesNov 21, 2024 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Secu...Show more |
A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulne...Show more |
2Fedoraproject Radare2Fedora Radare2Nov 21, 2024 Feb 23, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreNov 21, 2024 Feb 21, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outa...Show more |