CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Modsecurity 1Owasp Modsecurity Core Rule Set Nov 21, 2024 Apr 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted...Show more |
1Modsecurity 1Owasp Modsecurity Core Rule Set Nov 21, 2024 Apr 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted...Show more |
1Modsecurity 1Owasp Modsecurity Core Rule Set Nov 21, 2024 Apr 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted...Show more |
1Modsecurity 1Owasp Modsecurity Core Rule Set Nov 21, 2024 Apr 21, 2019 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted...Show more |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Aus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS |
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption. |
5Abb PhoenixcontactSchneider Electric+2 more106ed1052 1cc01 0ba8 Firmware 6es7211 1ae40 0xb0 Firmware6es7314 6eh04 0ab0 Firmware+7 moreJun 4, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network...Show more |
Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial of service (DoS) condition due to buffer space exhaustion. This issue only affects the SRX340 and SR...Show more |
A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high CPU condition leading to a Denial of Service (DoS). This issue affects only IPv4. Affected releases...Show more |
Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Junos OS device using the jdhcpd daemon configured to respond to IPv6 requests. Once started, memory c...Show more |
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request...Show more |
1Rockwellautomation 1Powerflex 525 Ac Drives Firmware Nov 21, 2024 Apr 4, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to c...Show more |
1Apple 5Icloud Iphone OsItunes+2 moreNov 21, 2024 Apr 3, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. |
1Ibm 1Websphere Application Server Nov 21, 2024 Apr 2, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CP...Show more |
2Canonical Nvidia17Geforce Gtx 745 Firmware Geforce Gtx 750 FirmwareGeforce Gtx 750 Ti Firmware+14 moreNov 21, 2024 Apr 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-s...Show more |
Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct denial-of-service attacks via client-initiated renegotiation. |
Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 seconds. The behavior...Show more |
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and...Show more |
A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE software could allow an unauthenticated, remote attacker to cause an interface wedge and an eventual de...Show more |
2Eclipse Fedoraproject2Fedora JettyNov 21, 2024 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames....Show more |