CWE-400
3,097 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,097)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreApr 29, 2026 Nov 26, 2010 N/A· v4 N/A· v3 8.3 HIGH· v2 The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory...Show more |
2Fedoraproject Linux2Fedora Linux KernelApr 29, 2026 Nov 26, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conju...Show more |
7Apple CanonicalDebian+4 more7Debian Linux FedoraLibpng+4 moreApr 29, 2026 Mar 3, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large unco...Show more |
Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unknown vectors. |
6Canonical FedoraprojectLinux+3 more8Esx FedoraLinux Kernel+5 moreApr 23, 2026 Oct 22, 2009 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on thi...Show more |
Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related...Show more |
Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related i...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Sep 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command...Show more |
The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related i...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 10, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU co...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 5, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the...Show more |
2Ledgersmb Sql Ledger2Ledgersmb Sql LedgerApr 23, 2026 Sep 15, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large Content-Length. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Aug 8, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove,...Show more |
Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process...Show more |
The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attackers to cause a denial of service (machine crash) via a flood of network traffi...Show more |
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in a...Show more |
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that trigge...Show more |
4Adobe MozillaNetscape+1 more4Acrobat Reader FirefoxNavigator+1 moreApr 23, 2026 Mar 10, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier th...Show more |
The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple cop...Show more |
Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (kernel panic) via unspecified vectors. |