CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hpe 1Integrated Lights Out 5 Firmware Jun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in H...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operations which result in a Denial-of-Service condition. A successful exploitation...Show more |
A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a...Show more |
2Debian Jettison Project2Debian Linux JettisonJun 17, 2026 Sep 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to cra...Show more |
2Fedoraproject Github2Cmark Gfm FedoraJun 17, 2026 Sep 15, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbound...Show more |
Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternate registry a speciall...Show more |
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO addre...Show more |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreJun 17, 2026 Sep 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Core and Visual Studio Denial of Service Vulnerability |
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device t...Show more |
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM...Show more |
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-node, an attacker can max out the number of client connections allowed by...Show more |
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations,...Show more |
JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto in Node.js, Browser, Cloudflare Workers, Electron, and Deno. The PBKDF2-based JWE key management alg...Show more |
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is t...Show more |
Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow each other's paynym. Then, the victim must try to collaborate with the attacker for a Stonewallx2 tr...Show more |
Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shells `Bash` and `Dash`, or any not-official...Show more |
2Debian Libvncserver Project2Debian Linux LibvncserverJun 17, 2026 Sep 2, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). |
1Qualcomm 17Apq8096au Firmware Qam8295p FirmwareQca6564a Firmware+14 moreJun 17, 2026 Sep 2, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto |
An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments extension could cause a site to become unavailable due to insufficient validation when certain actions...Show more |
2Netapp Redhat9Active Iq Unified Manager Cloud Secure AgentIntegration Camel K+6 moreJun 17, 2026 Sep 1, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. |