CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting t...Show more |
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 24, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Secu...Show more |
A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulne...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 23, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Feb 21, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outa...Show more |
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file. |
3Fedoraproject PrometheusRdo Project4Client Golang Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP s...Show more |
The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before v...Show more |
1Sap 2Netweaver Abap Netweaver As AbapJun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.4...Show more |
2Intel Netapp681Atom C3308 Atom C3336Atom C3338+678 moreJun 17, 2026 Feb 9, 2022 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. |
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non...Show more |
A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, which could lead to denial of service. This affects iSCSI SAN (Windows Nat...Show more |
Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime assumes that this invariant is satisfied. However, a `GraphDef` containing...Show more |
Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included in TensorFlow 2.8.0....Show more |
1Schneider Electric 6Modicon M340 Bmxp341000 Firmware Modicon M340 Bmxp342000 FirmwareModicon M340 Bmxp3420102 Firmware+3 moreJun 17, 2026 Feb 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of th...Show more |
5Debian FedoraprojectJenkins+2 more11Commerce Guided Search Communications Brm Elastic Charging EngineCommunications Cloud Native Core Automated Test Suite+8 moreJun 17, 2026 Feb 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel exe...Show more |
2Fedoraproject Mariadb2Fedora MariadbJun 17, 2026 Feb 1, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures. |
A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacke...Show more |