CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Audiocoding 1Freeware Advanced Audio Coder May 13, 2026 Jun 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file. |
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consum...Show more |
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consu...Show more |
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes. |
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (resour...Show more |
A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (Do...Show more |
2Netapp Php3Clustered Data Ontap PhpStorage Automation StoreMay 13, 2026 May 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted...Show more |
1Phoenix Contact Gmbh 1Mguard Firmware May 13, 2026 May 19, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the device's availability by performing multiple initial VPN requests. |
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router fro...Show more |
1Siemens 79Dk Standard Ethernet Controller Firmware Ek Ertec 200 Pn Io FirmwareEk Ertec 200p Pn Io Firmware+76 moreMay 13, 2026 May 11, 2017 7.1 HIGH· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PRO...Show more |
1Siemens 93Dk Standard Ethernet Controller Firmware Ek Ertec 200 Pn Io FirmwareEk Ertec 200p Pn Io Firmware+90 moreMay 13, 2026 May 11, 2017 7.1 HIGH· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interf...Show more |
1Rockwellautomation 2Compactlogix 5380 Firmware Controllogix 5580 FirmwareMay 13, 2026 May 6, 2017 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogi...Show more |
The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted image. |
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by c...Show more |
1Opendaylight 1Opendaylight May 13, 2026 Apr 24, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0. |
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communica...Show more |
1Juniper 1Northstar Controller May 13, 2026 Apr 24, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authenticated attacker to consume enough syste...Show more |
1Juniper 1Northstar Controller May 13, 2026 Apr 24, 2017 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to consume large amounts of system resources leading...Show more |
1Cisco 1Adaptive Security Appliance Software May 13, 2026 Apr 20, 2017 N/A· v4 4.0 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote att...Show more |
The iw_read_gif_file function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file. |