CWE-400
3,099 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,099)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Containers Image Project Redhat2Containers Image Enterprise LinuxNov 21, 2024 May 27, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use thi...Show more |
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when gett...Show more |
3Fedoraproject LinuxNetapp13Active Iq Unified Manager Cloud BackupFedora+10 moreNov 21, 2024 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system. |
2Netapp Ws Project2E Series Performance Analyzer WsNov 21, 2024 May 25, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed...Show more |
4Debian NetappRedhat+1 more4Debian Linux Enterprise LinuxLibwebp+1 moreNov 21, 2024 May 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. |
3Fedoraproject OpenidcOracle3Essbase FedoraMod Auth OpenidcNov 21, 2024 May 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. |
2Exiv2 Fedoraproject2Exiv2 FedoraNov 21, 2024 May 17, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier....Show more |
SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending HTTP requests ma...Show more |
ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Client before version 3.16.60 has a regular expression denial-of-service vulnerability. This was fixed in...Show more |
GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched i...Show more |
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions cou...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyNov 21, 2024 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3. |
1Siemens 18Simatic Hmi Comfort Outdoor Panels 15" Firmware Simatic Hmi Comfort Outdoor Panels 7" FirmwareSimatic Hmi Comfort Panels 22" Firmware+15 moreJun 2, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants)...Show more |
1Siemens 3Simatic Net Cp 343 1 Advanced Firmware Simatic Net Cp 343 1 Lean FirmwareSimatic Net Cp 343 1 Standard FirmwareNov 21, 2024 May 12, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Standard (incl. SIPLUS v...Show more |
Puma is a concurrent HTTP 1.1 server for Ruby/Rack applications. The fix for CVE-2019-16770 was incomplete. The original fix only protected existing connections that had already been accepted from having their requests s...Show more |
2Fedoraproject Matrix2Fedora SynapseNov 21, 2024 May 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify co...Show more |
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation. |
JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full...Show more |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreNov 21, 2024 May 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, when the BIG-IP system is buffering packet fragments for reassembly,...Show more |
2Eventlet Fedoraproject2Eventlet FedoraNov 21, 2024 May 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly co...Show more |