CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fernhillsoftware 1Scada Server Jun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. |
1Siemens 3Simatic Pcs Neo SinetplanTotally Integrated Automation PortalJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process speci...Show more |
1Siemens 12Simatic Cfu Diq Firmware Simatic Cfu Pa FirmwareSimatic S7 1500 Cpu Firmware+9 moreJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to c...Show more |
2Nekohtml Project Oracle2Nekohtml Weblogic ServerJun 17, 2026 Apr 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Apr 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents...Show more |
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to impact the performance of GitLab |
2Libtiff Netapp2Libtiff Ontap Select Deploy Administration UtilityJun 17, 2026 Apr 3, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments. |
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes. |
1Cloudfoundry 2Capi Release Cf DeploymentJun 17, 2026 Mar 25, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker...Show more |
4Ckeditor DrupalFedoraproject+1 more9Application Express CkeditorCommerce Merchandising+6 moreJun 17, 2026 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular...Show more |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4....Show more |
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specia...Show more |
4Fedoraproject NetappPython+1 more20Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+17 moreJun 17, 2026 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReD...Show more |
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate t...Show more |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreJun 17, 2026 Mar 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 .NET and Visual Studio Denial of Service Vulnerability |
3Debian FedoraprojectRust Lang3Debian Linux FedoraRegexJun 17, 2026 Mar 8, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trust...Show more |
6Canonical FedoraprojectNetapp+3 more17Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+14 moreJun 17, 2026 Mar 4, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU...Show more |
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, whic...Show more |