CWE-400
3,615 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,615)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles...Show more |
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...Show more |
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. |
1Microsoft 10Windows 10 1507 Windows 10 1607Windows 10 1809+7 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows CryptoAPI Denial of Service Vulnerability |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows Authentication Denial of Service Vulnerability |
1Microsoft 3Windows 11 21h2 Windows 11 22h2Windows Server 2022Jun 17, 2026 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP.sys Denial of Service Vulnerability |
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to cra...Show more |
1Siemens 6Simatic Mv540 H Firmware Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (...Show more |
1Siemens 6Simatic Mv540 H Firmware Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (...Show more |
AnyDesk 7.0.8 allows remote Denial of Service. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Jun 30, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth...Show more |
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local denial of service with System execution privileges needed. User interaction is not...Show more |
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. |
1Intellectualsites 1Fastasyncworldedit Jun 17, 2026 Jun 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibili...Show more |
1Microsoft 1Yet Another Reverse Proxy Jun 17, 2026 Jun 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability |
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel dur...Show more |
Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service
|
1Open Xchange 1Open Xchange Appsuite Backend Jun 17, 2026 Jun 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource us...Show more |
1Open Xchange 1Open Xchange Appsuite Backend Jun 17, 2026 Jun 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource us...Show more |
1Open Xchange 1Open Xchange Appsuite Backend Jun 17, 2026 Jun 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource us...Show more |