CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Citrix 3Application Delivery Controller Firmware GatewaySd WanJun 17, 2026 Dec 7, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a tempora...Show more |
1Citrix 2Application Delivery Controller Firmware GatewayJun 17, 2026 Dec 7, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disrupt...Show more |
2Calibre Ebook Fedoraproject2Calibre FedoraJun 17, 2026 Dec 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py. |
1Mitsubishi 55Melipc Mi5122 Vw Firmware Melsec Iq R R00 Cpu FirmwareMelsec Iq R R01 Cpu Firmware+52 moreJun 17, 2026 Dec 1, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120P...Show more |
1Businessdnasolutions 1Topease Jun 17, 2026 Nov 30, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated remote attacker with Object Modification p...Show more |
Dell Networking OS10, versions 10.4.3.x, 10.5.0.x, 10.5.1.x & 10.5.2.x, contain an uncontrolled resource consumption flaw in its API service. A high-privileged API user may potentially exploit this vulnerability, leading...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureJun 17, 2026 Nov 19, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device. |
1Intel 1Distribution Of Openvino Toolkit Jun 17, 2026 Nov 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access. |
1Intel 1Hardware Accelerated Execution Manager Jun 17, 2026 Nov 17, 2021 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable information disclosure via local access. |
1Intel 1Hardware Accelerated Execution Manager Jun 17, 2026 Nov 17, 2021 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privilege escalation via local access. |
2Bluez Debian2Bluez Debian LinuxJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be fre...Show more |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash). |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the con...Show more |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end. |
6Balasys F5Hpe+3 more30Arubaos Cx Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+27 moreAug 22, 2025 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculati...Show more |
2Debian Nlnetlabs2Debian Linux RoutinatorJun 17, 2026 Nov 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively s...Show more |
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user |
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests |
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests. |
1Image Processing Project 1Image Processing Jun 17, 2026 Nov 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file. |