CWE-400
3,101 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,101)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Cloudflare Debian2Debian Linux OctorpkiNov 21, 2024 Nov 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash). |
2Cloudflare Debian2Debian Linux OctorpkiNov 21, 2024 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the con...Show more |
2Cloudflare Debian2Debian Linux OctorpkiNov 21, 2024 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end. |
6Balasys F5Hpe+3 more30Arubaos Cx Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+27 moreAug 22, 2025 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculati...Show more |
2Debian Nlnetlabs2Debian Linux RoutinatorNov 21, 2024 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively s...Show more |
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user |
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests |
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests. |
1Image Processing Project 1Image Processing Nov 21, 2024 Nov 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file. |
Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of servic...Show more |
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. An attacker in a privileged network position may be able to perform denial of service. |
1Cisco 10Adaptive Security Appliance Software Asa 5505 FirmwareAsa 5512 X Firmware+7 moreNov 21, 2024 Oct 27, 2021 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote att...Show more |
1Cisco 11Adaptive Security Appliance Adaptive Security Appliance SoftwareAsa 5505 Firmware+8 moreNov 21, 2024 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of servi...Show more |
1Cisco 10Adaptive Security Appliance Software Asa 5505 FirmwareAsa 5512 X Firmware+7 moreNov 21, 2024 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS)...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selec...Show more |
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is...Show more |
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack. |
The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without lim...Show more |
The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functions. |
Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was found to be vulnerable to denial of service attacks to its reference table...Show more |