CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature |
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message. |
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system. |
2Fedoraproject Redhat2Etcd FedoraJun 17, 2026 Aug 6, 2020 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a...Show more |
In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu...Show more |
1Fanuc 16Power Motion I Model A Firmware Series 0i Mate D FirmwareSeries 0i Model B Firmware+13 moreJun 17, 2026 Aug 3, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreJun 17, 2026 Jul 30, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS. |
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas. |
2Elasticsearch Oracle4Communications Billing And Revenue Management Communications Cloud Native Core Network Function Cloud Native EnvironmentKibana+1 moreJun 17, 2026 Jul 27, 2020 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU...Show more |
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image. |
1Redhat 6Amq Jboss Ejb ClientJboss Enterprise Application Platform Continuous Delivery+3 moreJun 17, 2026 Jul 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavaila...Show more |
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is...Show more |
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to consume excessive system memory and cause a denial of service (DoS) condition on an...Show more |
1Cisco 3Sd Wan Firmware Vedge Cloud RouterVsmart ControllerJun 17, 2026 Jul 16, 2020 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of fields in Cisco SD-WAN pe...Show more |
In freewvs before 0.1.1, a directory structure of more than 1000 nested directories can interrupt a freewvs scan due to Python's recursion limit and os.walk(). This can be problematic in a case where an administrator sca...Show more |
In freewvs before 0.1.1, a user could create a large file that freewvs will try to read, which will terminate a scan process. This has been patched in 0.1.1. |
1Siemens 13Opcenter Execution Discrete Opcenter Execution FoundationOpcenter Execution Process+10 moreJun 17, 2026 Jul 14, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All...Show more |
1Siemens 2Simatic S7 200 Smart Sr Cpu Firmware Simatic S7 200 Smart St Cpu FirmwareJun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly handle large numbers of new incomming connections and could crash under certain cir...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 7, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 7, 2020 N/A· v4 8.8 HIGH· v3 6.1 MEDIUM· v2 An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables...Show more |