CWE-400
3,615 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,615)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart. |
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
|
Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.
|
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service
|
1Silabs 1Bluetooth Low Energy Software Development Kit Jun 17, 2026 Jun 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears th...Show more |
1Bosch 2Cpp13 Firmware Cpp14 FirmwareJun 17, 2026 Jun 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video strea...Show more |
IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588. |
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Jun 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Windows Hyper-V Denial of Service Vulnerability |
1Rockwellautomation 1Factorytalk Transaction Manager Jun 17, 2026 Jun 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentia...Show more |
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms |
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files. |
A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the function filterKeyword. The manipulation of the argument value leads to resource consumption. VDB-231090 is...Show more |
zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which are using the second argument of the zxcvbn function. It can result in...Show more |
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the...Show more |
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the...Show more |
2Fast Xml Parser Project Naturalintelligence2Fast Xml Parser Fast Xml ParserJun 17, 2026 Jun 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searchi...Show more |
1Qualcomm 21Qca6574au Firmware Qca6595au FirmwareQca6696 Firmware+18 moreJun 17, 2026 Jun 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue. |
1Mozilla 3Firefox Firefox MobileFocusAug 19, 2026 Jun 2, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android <...Show more |
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond...Show more |