CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an uncontrolled resource consumption vulnerability. A large amount of page moves within a short space of...Show more |
2Bindata Project Gitlab2Bindata GitlabJun 17, 2026 Jun 24, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinDat...Show more |
Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container proces...Show more |
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection,...Show more |
1Sing4g 14gee Router Hh70vb Firmware Jun 17, 2026 Jun 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, u...Show more |
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the conne...Show more |
1Citrix 4Application Delivery Controller Firmware GatewayNetscaler Gateway+1 moreJun 17, 2026 Jun 16, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a s...Show more |
2Apache Oracle5Business Intelligence Communications Element ManagerCommunications Messaging Server+2 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This...Show more |
1Nextcloud 1End To End Encryption Jun 17, 2026 Jun 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated users to lock files of other users. |
The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. I...Show more |
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Caref...Show more |
A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources. |
1Mitsubishielectric 20R00cpu Firmware R01cpu FirmwareR02cpu Firmware+17 moreJun 17, 2026 Jun 11, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU a...Show more |
1Intel 13Dsl5320 Thunderbolt 2 Firmware Dsl5520 Thunderbolt 2 FirmwareDsl6340 Thunderbolt 3 Firmware+10 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. |
1Intel 13Dsl5320 Thunderbolt 2 Firmware Dsl5520 Thunderbolt 2 FirmwareDsl6340 Thunderbolt 3 Firmware+10 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. |
1Bosch 5Cpp13 Firmware Cpp4 FirmwareCpp6 Firmware+2 moreJun 17, 2026 Jun 9, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that causes the camera to become unresponsive for a few seconds and cause a Denial of Service (DoS). |
1Siemens 25Simatic Reader Rf610r Cmiit Firmware Simatic Reader Rf610r Etsi FirmwareSimatic Reader Rf610r Fcc Firmware+22 moreJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2), SIMATIC RF186C (All versions > V1.1 and < V1.3.2), SIMATIC RF186CI (All version...Show more |
A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a very long issue or merge request description |
An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different...Show more |