CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 28Mdm9206 Firmware Mdm9607 FirmwareMdm9640 Firmware+25 moreNov 21, 2024 May 24, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads to out of bound memory access. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Elec...Show more |
1Mitsubishielectric 1Qj71e71 100 Firmware Nov 21, 2024 May 23, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against the FTP service, forcing the target devices to enter an error mode and...Show more |
1Schneider Electric 2Modicon M221 Firmware Somachine BasicMay 29, 2026 May 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet...Show more |
2Microsoft Redhat6.net Core .net FrameworkEnterprise Linux+3 moreNov 21, 2024 May 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, C...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. Making concurrent GET /api/v4/projects/<id>/languages requests may allow Uncontrolled Reso...Show more |
1Cisco 27Sf300 08 Firmware Sf300 24 FirmwareSf300 24mp Firmware+24 moreNov 21, 2024 May 16, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on sys...Show more |
1Siemens 6Sinamics Perfect Harmony Gh180 With Nxg I Control Mlfb 6sr2 Firmware Sinamics Perfect Harmony Gh180 With Nxg I Control Mlfb 6sr3 FirmwareSinamics Perfect Harmony Gh180 With Nxg I Control Mlfb 6sr4 Firmware+3 moreNov 21, 2024 May 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G28), SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR...Show more |
1Virginmedia 1Hub 3.0 Firmware Nov 21, 2024 May 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Virgin Media wireless router 3.0 hub devices, the web interface is vulnerable to denial of service. When POST requests are sent and keep the connection open, the router lags and becomes unusable to anyone currently us...Show more |
In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function format8BIM, which allows attackers to cause a denial of service. |
In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function ReadTIFFImage, which allows attackers to cause a denial of service. |
The iwgif_init_screen function in imagew-gif.c:510 in ImageWorsener 1.3.2 allows remote attackers to cause a denial of service (hmemory exhaustion) via a crafted file. |
1Phoenixcontact 29Fl Switch 3004t Fx Firmware Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 moreNov 21, 2024 May 7, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections. |
1Cisco 1Firepower Threat Defense Nov 21, 2024 May 3, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a d...Show more |
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected de...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Management CenterNov 26, 2024 May 3, 2019 N/A· v4 7.4 HIGH· v3 3.3 LOW· v2 Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a d...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseNov 21, 2024 May 3, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU uti...Show more |
1Rockwellautomation 4Armor Compact Guardlogix 5370 Firmware Compactlogix 5370 L1 FirmwareCompactlogix 5370 L2 Firmware+1 moreFeb 20, 2026 May 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recoveri...Show more |
1Fujifilm 3Cr Ir 357 Fcr Capsula X Firmware Cr Ir 357 Fcr Carbon X FirmwareCr Ir 357 Fcr Xc 2 FirmwareNov 21, 2024 Apr 30, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptible to a denial-of-service condition as a result of an overflow of TCP packets,...Show more |
7Canonical DebianHp+4 more16Debian Linux Enterprise LinuxEnterprise Linux Desktop+13 moreNov 21, 2024 Apr 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploit...Show more |
1Modsecurity 1Owasp Modsecurity Core Rule Set Nov 21, 2024 Apr 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted...Show more |