CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability...Show more |
1Cisco 3Cgr1000 Firmware Ic3000 Industrial Compute Gateway FirmwareIosJun 17, 2026 Mar 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute...Show more |
2Netapp Redhat4Active Iq Unified Manager Jboss Enterprise Application PlatformJboss Remoting+1 moreJun 17, 2026 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versi...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreJun 17, 2026 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and wil...Show more |
6Apache DebianFedoraproject+3 more13Activemq Banking Enterprise Default ManagementBanking Platform+10 moreJun 17, 2026 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on...Show more |
2Netapp Schema Inspector Project3E Series Performance Analyzer Oncommand InsightSchema InspectorJun 17, 2026 Mar 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (...Show more |
2Fedoraproject Torproject2Fedora TorJun 17, 2026 Mar 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. |
5Fedoraproject Lldpd ProjectOpenvswitch+2 more17Enterprise Linux FedoraLldpd+14 moreJun 17, 2026 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more |
2Debian Teluu2Debian Linux PjsipJun 17, 2026 Mar 10, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial...Show more |
1Netgear 2Gs116e Firmware Jgs516pe FirmwareJun 17, 2026 Mar 10, 2021 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack...Show more |
2Linux Oracle2Linux Kernel Tekelec Platform DistributionJun 17, 2026 Mar 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting ava...Show more |
Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vulnerability involving the HTTP JSON-RPC API service. If username and pa...Show more |
5Fedoraproject NetappNodejs+2 more9E Series Performance Analyzer FedoraGraalvm+6 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If...Show more |
1Trendmicro 19Apex Central Apex OneCloud Edge+16 moreJun 17, 2026 Mar 3, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a sp...Show more |
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted. |
5Apache DebianEclipse+2 more16Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services+13 moreJun 17, 2026 Feb 26, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may en...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Feb 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver cou...Show more |
1Abb 6Pm554 Firmware Pm556 FirmwarePm564 Firmware+3 moreJun 17, 2026 Feb 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC...Show more |
Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited request...Show more |
UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash. |