CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a possible ReDoS vulnerability (Regular Expression Denial of Service) when u...Show more |
A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to...Show more |
1Phoenixcontact 3Btp 2043w Firmware Btp 2070w FirmwareBtp 2102w FirmwareJun 17, 2026 Dec 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Serv...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentJun 17, 2026 Dec 2, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML p...Show more |
2Debian Gorillatoolkit2Debian Linux WebsocketJun 17, 2026 Dec 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket c...Show more |
1Mitsubishielectric 19R00cpu Firmware R01cpu FirmwareR02cpu Firmware+16 moreJun 17, 2026 Nov 30, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Vali...Show more |
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of q...Show more |
1Djvalidator Project 1Djvalidator Jun 17, 2026 Nov 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@---------------------------------------------------------------------...Show more |
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4. |
1Mitsubishielectric 28R00cpu Firmware R01cpu FirmwareR02cpu Firmware+25 moreJun 17, 2026 Nov 20, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/120SFCPU firmware vers...Show more |
4C Ares Project FedoraprojectNodejs+1 more8Blockchain Platform C AresFedora+5 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a D...Show more |
An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected...Show more |
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high C...Show more |
1Mitsubishielectric 8Melsec Iq R00 Firmware Melsec Iq R01 FirmwareMelsec Iq R02 Firmware+5 moreJun 17, 2026 Nov 16, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacke...Show more |
1Siemens 12Simatic S7 300 Cpu 312 Firmware Simatic S7 300 Cpu 314 FirmwareSimatic S7 300 Cpu 315 2 Dp Firmware+9 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specia...Show more |
1Bab Technologie 1Eibport Firmware Jun 17, 2026 Nov 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd component. |
1Express Validators Project 1Express Validators Jun 17, 2026 Nov 11, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls. |
In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service requiring a device reset to fix with no additional execu...Show more |
1Mitsubishielectric 51Melsec Iq R00cpu Firmware Melsec Iq R01cpu FirmwareMelsec Iq R02cpu Firmware+48 moreJun 17, 2026 Nov 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlie...Show more |
2Codemirror Oracle6Application Express CodemirrorEnterprise Manager Express User Interface+3 moreJun 17, 2026 Oct 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac7...Show more |