CWE-400
3,601 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,601)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Mongodb2Bson FedoraNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue...Show more |
The IPv6 implementation in Apple Mac OS X (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entr...Show more |
The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing...Show more |
1Microsoft 4Windows 7 Windows Server 2003Windows Vista+1 moreNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries. |
The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability...Show more |
1Microsoft 4Windows 7 Windows Server 2003Windows Vista+1 moreNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2010-4669. |
1Cisco 2Cloud Email Security Email Security ApplianceJun 17, 2026 Feb 19, 2020 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condit...Show more |
4Canonical LinuxNetapp+1 more10Active Iq Unified Manager Cloud BackupData Availability Services+7 moreJun 17, 2026 Feb 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. |
Adobe Experience Manager versions 6.5, and 6.4 have an uncontrolled resource consumption vulnerability. Successful exploitation could lead to denial-of-service. |
1Avira 10Antivir Mailgate Antivir Mailgate SuiteAntivir Personal+7 moreNov 21, 2024 Feb 12, 2020 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine. |
4Apple FreebsdOpenbsd+1 more4Freebsd Mac Os XOpenbsd+1 moreNov 21, 2024 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion. |
The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock con...Show more |
1Siemens 52Dk Standard Ethernet Controller Ek Ertec 200 FirmwareEk Ertec 200p Firmware+49 moreJun 17, 2026 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of ser...Show more |
1Siemens 24S7 1200 Cpu 1211c Firmware S7 1200 Cpu 1212c FirmwareS7 1200 Cpu 1212fc Firmware+21 moreJun 17, 2026 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC ET 200pro IM154-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8F PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8FX PN/DP CPU (All versions < V3...Show more |
1Siemens 4Scalance S602 Firmware Scalance S612 FirmwareScalance S623 Firmware+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >=...Show more |
1Siemens 4Scalance S602 Firmware Scalance S612 FirmwareScalance S623 Firmware+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >=...Show more |
4Canonical CephOpensuse+1 more4Ceph LeapOpenshift Container Storage+1 moreJun 17, 2026 Feb 7, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket conn...Show more |
2Fedoraproject Nghttp22Fedora Nghttp2Nov 21, 2024 Feb 6, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion). |
A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application. |
3Canonical NetappPython3Active Iq Unified Manager PythonUbuntu LinuxJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb. |