CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PIVX through 3.1.03 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid he...Show more |
navcoin through 4.3.0 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM. |
HTMLCOIN through 2.12 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM. |
particl through 0.17 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM. |
emercoin through 0.7 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM. |
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system. |
1Google 1Nest Cam Iq Indoor Firmware Nov 21, 2024 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service....Show more |
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially cra...Show more |
qtum through 0.16 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM. |
1Cisco 7Aironet 1540 Firmware Aironet 1560 FirmwareAironet 1850 Firmware+4 moreNov 21, 2024 Oct 16, 2019 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause...Show more |
2Csv Parse Project Fedoraproject2Csv Parse FedoraNov 21, 2024 Oct 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is...Show more |
1Siemens 1Simatic Winac Rtx F 2010 Nov 21, 2024 Oct 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain a vulnerability that could allow an unauthenticated attacker to trigger a denial-...Show more |
1Siemens 66Dk Standard Ethernet Controller Firmware Ek Ertec 200 FirmwareEk Ertec 200p Firmware+63 moreNov 21, 2024 Oct 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected devices improperly handle large amounts of specially crafted UDP packets.
This could allow an unauthenticated remote attacker to trigger a denial of service condition. |
1Siemens 40Cp1604 Firmware Cp1616 FirmwareDk Standard Ethernet Controller Firmware+37 moreNov 21, 2024 Oct 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation. |
A memory leak vulnerability in the of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending specific commands from a peered BGP host and having those BGP states delivere...Show more |
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The implementation in versions 1.10.0 through 1...Show more |
1Fon 4Fon2601e Fsw B Firmware Fon2601e Fsw S FirmwareFon2601e Re Firmware+1 moreNov 21, 2024 Oct 4, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue where they may behave as open resolvers. If this vulnerability is exploited, FON routers may be lever...Show more |
1Cisco 13Adaptive Security Appliance Software Asa 5505 FirmwareAsa 5510 Firmware+10 moreNov 21, 2024 Oct 2, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker...Show more |
1Cisco 1Ic3000 Industrial Compute Gateway Firmware Nov 21, 2024 Oct 2, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulne...Show more |
1Cisco 4Firepower 9300 Firmware Firepower Extensible Operating SystemFirepower Threat Defense+1 moreNov 26, 2024 Oct 2, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could all...Show more |