CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. |
2Debian Vmware2Debian Linux RabbitmqJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending mali...Show more |
1Redhat 1Machine Config Operator Jun 17, 2026 Jun 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memory. An attacker could use this flaw to deny access to schedule new pods...Show more |
1Cisco 2Video Surveillance 7070 Firmware Video Surveillance 7530pd FirmwareJun 17, 2026 Jun 4, 2021 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacke...Show more |
1Cisco 2Video Surveillance 7070 Firmware Video Surveillance 7530pd FirmwareJun 17, 2026 Jun 4, 2021 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacke...Show more |
2Gulpjs Oracle2Communications Cloud Native Core Policy Glob ParentJun 17, 2026 Jun 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator. |
A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected me...Show more |
2Oracle Redhat14Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+11 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affec...Show more |
2Netapp Redhat3Integration Camel K Oncommand InsightResteasyJun 17, 2026 Jun 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with higher CPU time spent searching and adding the entry. This flaw allows...Show more |
Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20.0.10, and 21.0.2, a malicious user may be able to break the user administration page. This would dis...Show more |
3Debian NetappTrim Newlines Project3Debian Linux E Series Performance AnalyzerTrim NewlinesJun 17, 2026 May 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method. |
An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive...Show more |
2Redhat Spice Project2Enterprise Linux SpiceJun 17, 2026 May 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection. |
2Containers Image Project Redhat2Containers Image Enterprise LinuxJun 17, 2026 May 27, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use thi...Show more |
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when gett...Show more |
3Fedoraproject LinuxNetapp13Active Iq Unified Manager Cloud BackupFedora+10 moreJun 17, 2026 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system. |
2Netapp Ws Project2E Series Performance Analyzer WsJun 17, 2026 May 25, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed...Show more |
4Debian NetappRedhat+1 more4Debian Linux Enterprise LinuxLibwebp+1 moreJun 17, 2026 May 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. |
3Fedoraproject OpenidcOracle3Essbase FedoraMod Auth OpenidcJun 17, 2026 May 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. |
2Exiv2 Fedoraproject2Exiv2 FedoraJun 17, 2026 May 17, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier....Show more |