← Back
CWE-400

3,101 CVEs • Abstraction: Class • Likelihood of Exploit: High

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

JSON object

Loading...

CVEs (3,101)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Cloudflare
Debian
2Debian Linux
Octorpki
Nov 21, 2024
Nov 11, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
2Cloudflare
Debian
2Debian Linux
Octorpki
Nov 21, 2024
Nov 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the con...Show more
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.Show less
2Cloudflare
Debian
2Debian Linux
Octorpki
Nov 21, 2024
Nov 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
6Balasys
F5Hpe+3 more
30Arubaos Cx
Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+27 more
Aug 22, 2025
Nov 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculati...Show more
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.Show less
2Debian
Nlnetlabs
2Debian Linux
Routinator
Nov 21, 2024
Nov 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively s...Show more
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this time-out was only applied to individual read or write operations rather than the complete request. Thus, if an RRDP repository sends a little bit of data before that time-out expired, it can continuously extend the time it takes for the request to finish. Since validation will only continue once the update of an RRDP repository has concluded, this delay will cause validation to stall, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Nov 4, 2021
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user
1Fortinet
1Fortiweb
Nov 21, 2024
Nov 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests
1Fortinet
1Fortiportal
Nov 21, 2024
Nov 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests.
1Image Processing Project
1Image Processing
Nov 21, 2024
Nov 2, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.
1Fluentd
1Fluentd
Nov 21, 2024
Oct 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of servic...Show more
Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. This issue is patched in version 1.14.2 There are two workarounds available. Either don't use parser_apache2 for parsing logs (which cannot guarantee generated by Apache), or put patched version of parser_apache2.rb into /etc/fluent/plugin directory (or any other directories specified by the environment variable `FLUENT_PLUGIN` or `--plugin` option of fluentd).Show less
1Apple
1Macos
Nov 21, 2024
Oct 28, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. An attacker in a privileged network position may be able to perform denial of service.
1Cisco
10Adaptive Security Appliance Software
Asa 5505 FirmwareAsa 5512 X Firmware+7 more
Nov 21, 2024
Oct 27, 2021
N/A· v4
6.5 MEDIUM· v3
6.3 MEDIUM· v2
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote att...Show more
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is due to improper control of a resource. An attacker with the ability to spoof a trusted IKEv2 site-to-site VPN peer and in possession of valid IKEv2 credentials for that peer could exploit this vulnerability by sending malformed, authenticated IKEv2 messages to an affected device. A successful exploit could allow the attacker to trigger a reload of the device.Show less
1Cisco
11Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5505 Firmware+8 more
Nov 21, 2024
Oct 27, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of servi...Show more
A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS packets are not properly processed. An attacker could exploit this vulnerability by sending a crafted SSL/TLS packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.Show less
1Cisco
10Adaptive Security Appliance Software
Asa 5505 FirmwareAsa 5512 X Firmware+7 more
Nov 21, 2024
Oct 27, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS)...Show more
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacker could exploit this vulnerability by opening a significant number of connections on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.Show less
1Cloudfoundry
2Capi Release
Cf Deployment
Nov 21, 2024
Oct 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selec...Show more
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query.Show less
1Freeswitch
1Freeswitch
Nov 21, 2024
Oct 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is...Show more
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Denial of Service via SIP flooding. When flooding FreeSWITCH with SIP messages, it was observed that after a number of seconds the process was killed by the operating system due to memory exhaustion. By abusing this vulnerability, an attacker is able to crash any FreeSWITCH instance by flooding it with SIP messages, leading to Denial of Service. The attack does not require authentication and can be carried out over UDP, TCP or TLS. This issue was patched in version 1.10.7.Show less
1Gjson Project
1Gjson
Nov 21, 2024
Oct 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
1Auvesy
1Versiondog
Nov 21, 2024
Oct 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without lim...Show more
The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp folder of the webinstaller executable.Show less
1Auvesy
1Versiondog
Nov 21, 2024
Oct 22, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functions.
1Reddit
1Snudown
Nov 21, 2024
Oct 21, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was found to be vulnerable to denial of service attacks to its reference table...Show more
Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was found to be vulnerable to denial of service attacks to its reference table implementation. References written in markdown ` [reference_name]: https://www.example.com` are inserted into a hash table which was found to have a weak hash function, meaning that an attacker can reliably generate a large number of collisions for it. This makes the hash table vulnerable to a hash-collision DoS attack, a type of algorithmic complexity attack. Further the hash table allowed for duplicate entries resulting in long retrieval times. Proofs of concept and further discussion of the hash collision issue are discussed on the snudown GHSA(https://github.com/reddit/snudown/security/advisories/GHSA-6gvv-9q92-w5f6). Users are advised to update to version 1.7.0.Show less