CWE-400
3,615 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,615)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files. |
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28. |
3Apple HaxxNetapp8Clustered Data Ontap CurlH300s Firmware+5 moreJun 17, 2026 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows...Show more |
3Avahi FedoraprojectRedhat3Avahi Enterprise LinuxFedoraJun 17, 2026 May 26, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. |
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseJun 17, 2026 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when clien...Show more |
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty. |
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into acc...Show more |
3C Ares Project DebianFedoraproject3C Ares Debian LinuxFedoraJun 17, 2026 May 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target reso...Show more |
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a...Show more |
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact. |
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition. |
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 20...Show more |
1Westerndigital 4My Cloud Home Duo Firmware My Cloud Home FirmwareMy Cloud Os 5+1 moreJun 17, 2026 May 18, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was...Show more |
2Libreswan Redhat5Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+2 moreJun 17, 2026 May 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero re...Show more |
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when...Show more |
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed...Show more |
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges ne...Show more |
2Opcfoundation Prosysopc4Ua Historian Ua Java LegacyUa Modbus Server+1 moreJun 17, 2026 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications. |
1Sick 7Ftmg Esd15axx Firmware Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 moreJun 17, 2026 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by in...Show more |