CWE-400
3,099 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,099)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trendmicro 19Apex Central Apex OneCloud Edge+16 moreNov 21, 2024 Mar 3, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a sp...Show more |
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted. |
5Apache DebianEclipse+2 more16Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services+13 moreAug 20, 2025 Feb 26, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may en...Show more |
2Fedoraproject Matrix2Fedora SynapseNov 21, 2024 Feb 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver cou...Show more |
1Abb 6Pm554 Firmware Pm556 FirmwarePm564 Firmware+3 moreNov 21, 2024 Feb 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC...Show more |
Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited request...Show more |
UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash. |
1Redhat 3Jboss Fuse Openshift Application RuntimesUndertowNov 21, 2024 Feb 23, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. Th...Show more |
1Qualcomm 415Aqt1000 Firmware Ar7420 FirmwareAr8031 Firmware+412 moreNov 21, 2024 Feb 22, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C...Show more |
1Scrapbox Parser Project 1Scrapbox Parser Nov 21, 2024 Feb 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js. |
This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require('three') function build_blank (n) { var ret = "rgb(" for (var i = 0; i < n; i++) { ret += " " } ret...Show more |
A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condi...Show more |
1Intel 1Ethernet Network Adapter E810 Firmware Nov 21, 2024 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access. |
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exha...Show more |
uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0, some regexes are vulnerable to regular expression denial of service (...Show more |
1Mbconnectline 2Mbconnect24 Mymbconnect24Nov 21, 2024 Feb 16, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creat...Show more |
1Ibm 1Spectrum Protect Operations Center Nov 21, 2024 Feb 15, 2021 N/A· v4 4.8 MEDIUM· v3 2.3 LOW· v2 IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file. By setting a grossly large cache value and dumping...Show more |
2Apache Oracle4Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core PolicyHive+1 moreNov 21, 2024 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. |
1F5 1Big Ip Application Security Manager Nov 21, 2024 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack agai...Show more |
2Fedoraproject Rubyonrails2Fedora RailsNov 21, 2024 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` ty...Show more |