CWE-400
3,262 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,262)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by send...Show more |
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can exploit this issue to render the affect...Show more |
The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +)...Show more |
ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service (server hang and logfile flooding) via a one bit BMP file. |
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption)...Show more |
1Moxa 10Nport 5100 Series Firmware Nport 5100a Series FirmwareNport 5200 Series Firmware+7 moreJun 2, 2026 Feb 13, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series version...Show more |
1Schneider Electric 8Magelis Gto Advanced Optimum Panel Firmware Magelis Gtu Universal Panel FirmwareMagelis Sto5 Small Panel Firmware+5 moreMay 13, 2026 Feb 13, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Ad...Show more |
1Schneider Electric 8Magelis Gto Advanced Optimum Panel Firmware Magelis Gtu Universal Panel FirmwareMagelis Sto5 Small Panel Firmware+5 moreMay 13, 2026 Feb 13, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Ad...Show more |
Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR. |
2Debian Mini Xml Project2Debian Linux Mini XmlMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. |
2Debian Mini Xml Project2Debian Linux Mini XmlMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. |
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a bu...Show more |
NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via an ntpdc relist command, which triggers recursive traversal of the restriction list. |
3Momentjs OracleTenable3Moment NessusPrimavera UnifierMay 13, 2026 Jan 23, 2017 N/A· v4 6.5 MEDIUM· v3 7.8 HIGH· v2 The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)." |
1Fiberhome 1Fengine S5800 Firmware May 13, 2026 Jan 23, 2017 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger a...Show more |
The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet. |
ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet. |
The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet. |
4Canonical HpeNtp+1 more9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+6 moreMay 13, 2026 Jan 13, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sou...Show more |
Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads. The Samsung ID is SVE-2016-7650. |