CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string. |
4Canonical DebianOracle+1 more4Debian Linux GeorasterOpenjpeg+1 moreNov 21, 2024 Feb 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. |
2Apport Project Canonical2Apport Ubuntu LinuxNov 3, 2025 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resour...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhau...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion...Show more |
A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from accepting new connections. |
In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf...Show more |
2Ibm Lenova42Bladecenter Hs22 Firmware Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 moreNov 21, 2024 Jan 26, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a hi...Show more |
3Canonical DebianDovecot3Debian Linux DovecotUbuntu LinuxNov 21, 2024 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration whe...Show more |
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. |
2Debian Redhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply. |
1Siemens 1Telecontrol Server Basic Nov 21, 2024 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver (port 80/tcp or 443/tcp) could cause a Denial-of-Service condition on the web se...Show more |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxNov 21, 2024 Jan 19, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This...Show more |
1Cisco 1Unified Computing System Central Software Nov 21, 2024 Jan 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted de...Show more |
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This c...Show more |
1Cisco 1Unified Customer Voice Portal Nov 21, 2024 Jan 18, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerab...Show more |
In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received. This could lead to a remote denial of service of a critical system pr...Show more |
A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxNov 21, 2024 Jan 3, 2018 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service. |
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1. |