CWE-400
3,099 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,099)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Iportalis 1Iportalis Control Portal Nov 21, 2024 Sep 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote server until memory is exh...Show more |
3Axios OracleSiemens3Axios GoldengateSinec InsNov 21, 2024 Aug 31, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 axios is vulnerable to Inefficient Regular Expression Complexity |
Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially t...Show more |
1Passport Saml Project 1Passport Saml Nov 21, 2024 Aug 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payload can require transforms that consume significant system resources to p...Show more |
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially c...Show more |
1Intel 1Ethernet Controller E810 Firmware Nov 21, 2024 Aug 11, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow privileged user to potentially enable denial of service via loc...Show more |
1Siemens 1Automation License Manager Nov 21, 2024 Aug 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2). Sending specially crafted packets to port 4410/tcp of an affected syste...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelNov 21, 2024 Aug 5, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN ca...Show more |
1Fortinet 2Fortiauthenticator FortisandboxNov 21, 2024 Aug 4, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow...Show more |
Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS...Show more |
The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs, which allowed an attacker to cause a denial of service. |
Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An authenticated remote attacker can cause a Denial of Service due to overlo...Show more |
OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `quote` method that implements the logic behind the Quote button in the...Show more |
Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU. |
Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU. |
2Oracle Sheetjs3Rest Data Services SheetjsSheetjs ProNov 21, 2024 Jul 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js. |
2Oracle Sheetjs Project3Rest Data Services SheetjsSheetjs ProNov 21, 2024 Jul 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2). |
2Oracle Sheetjs Project3Rest Data Services SheetjsSheetjs ProNov 21, 2024 Jul 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2). |
An Uncontrolled Resource Consumption vulnerability in the ARP daemon (arpd) and Network Discovery Protocol (ndp) process of Juniper Networks Junos OS Evolved allows a malicious attacker on the local network to consume me...Show more |
An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sending large amounts of legitimate traffic destined to the device to cause...Show more |