CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3Jboss Fuse Openshift Application RuntimesUndertowJun 17, 2026 Feb 23, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. Th...Show more |
1Qualcomm 415Aqt1000 Firmware Ar7420 FirmwareAr8031 Firmware+412 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C...Show more |
1Scrapbox Parser Project 1Scrapbox Parser Jun 17, 2026 Feb 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js. |
This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require('three') function build_blank (n) { var ret = "rgb(" for (var i = 0; i < n; i++) { ret += " " } ret...Show more |
A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condi...Show more |
1Intel 1Ethernet Network Adapter E810 Firmware Jun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access. |
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exha...Show more |
uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0, some regexes are vulnerable to regular expression denial of service (...Show more |
1Mbconnectline 2Mbconnect24 Mymbconnect24Jun 17, 2026 Feb 16, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creat...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Feb 15, 2021 N/A· v4 4.8 MEDIUM· v3 2.3 LOW· v2 IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file. By setting a grossly large cache value and dumping...Show more |
2Apache Oracle4Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core PolicyHive+1 moreJun 17, 2026 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. |
1F5 1Big Ip Application Security Manager Jun 17, 2026 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack agai...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` ty...Show more |
3Debian FedoraprojectOpenvswitch3Debian Linux FedoraOpenvswitchJun 17, 2026 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be to...Show more |
Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This...Show more |
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM X-Force ID: 193659. |
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can a...Show more |
httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of...Show more |
Trend Micro Antivirus for Mac 2021 (Consumer) is vulnerable to a memory exhaustion vulnerability that could lead to disabling all the scanning functionality within the application. Please note: an attacker must first obt...Show more |
1Cisco 1Managed Services Accelerator Jun 17, 2026 Feb 4, 2021 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the REST API of Cisco Managed Services Accelerator (MSX) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to th...Show more |