CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There is a resource management errors vulnerability in Huawei P30. Local attackers construct broadcast message for some application, causing this application to send this broadcast message and impact the customer's use e...Show more |
2Jqueryvalidation Netapp2Jquery Validation SnapcenterJun 17, 2026 Jan 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions th...Show more |
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport. |
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the py...Show more |
1Kamadak Exif Project 1Kamadak Exif Jun 17, 2026 Jan 6, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. Specifically, reader::read_from_container can cause an infinite loop wh...Show more |
1Dell 3Emc Unity Operating Environment Emc Unity Vsa Operating EnvironmentEmc Unity Xt Operating EnvironmentJun 17, 2026 Jan 5, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerabili...Show more |
1Trust Dns Server Project 1Trust Dns Server Jun 17, 2026 Dec 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption. |
An issue was discovered in the image crate before 0.23.12 for Rust. A Mutable reference has immutable provenance. (In the case of LLVM, the IR may be always correct.) |
1Date And Time Project 1Date And Time Jun 17, 2026 Dec 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed...Show more |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Dec 24, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption. |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Dec 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may c...Show more |
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions. |
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages. |
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums. |
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. Du...Show more |
Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior...Show more |
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-service vulnerability can make a LES server crash via malicious GetProofsV2 request from a...Show more |
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields. |
1Wago 10750 331 Firmware 750 352 Firmware750 829 Firmware+7 moreJun 17, 2026 Dec 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack. |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Dec 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by...Show more |