CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Pureftpd2Fedora Pure FtpdNov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. |
2Fedoraproject Freeciv2Fedora FreecivNov 21, 2024 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exha...Show more |
A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.patch, and 2.6.37.4-test14.patch. A bad bounds check in arch_get_unmapped_area_topdown triggered by pro...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow...Show more |
1F5 1Big Ip Application Security Manager Nov 21, 2024 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP ASM system may consume excessive resources when processing certain types of HTTP responses from the origin web...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+11 moreNov 21, 2024 Dec 22, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that...Show more |
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page. |
1Jenkins 1Build Failure Analyzer Nov 21, 2024 Dec 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way that wasn't interruptible, allowing attackers to have Jenkins evaluate a regular expression without th...Show more |
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors |
2Apache Debian2Debian Linux SpamassassinNov 21, 2024 Dec 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. |
1Ovislink 1Airlive Poe2600hd Firmware Nov 21, 2024 Dec 11, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL. |
Katello has a Denial of Service vulnerability in API OAuth authentication |
1Weidmueller 40Ie Sw Pl08m 6tx 2sc Firmware Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 moreNov 21, 2024 Dec 6, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a device with a special pack...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreNov 21, 2024 Nov 29, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of se...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Nov 27, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic for a Virtual Server w...Show more |
2Fedoraproject Freeipa2Fedora FreeipaNov 21, 2024 Nov 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, w...Show more |
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a ser...Show more |
2Debian Phpldapadmin Project2Debian Linux PhpldapadminNov 21, 2024 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via special...Show more |
The use of `String.to_atom/1` in PowAssent is susceptible to denial of service attacks. In `PowAssent.Phoenix.AuthorizationController` a value is fetched from the user provided params, and `String.to_atom/1` is used to c...Show more |
5Broadcom DebianFedoraproject+2 more5Debian Linux FedoraOpenstack+2 moreApr 2, 2025 Nov 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more |