CWE-400
3,601 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,601)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Firepower System Software Nov 21, 2024 Nov 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured Intrusion Prevention System (IPS) rule that inspects certain types of TCP...Show more |
1Cisco 2Advanced Malware Protection For Endpoints Immunet For EndpointsNov 21, 2024 Nov 8, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker proce...Show more |
4Apple CanonicalDebian+1 more4Debian Linux NginxUbuntu Linux+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default)...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by...Show more |
2Cached Path Relative Project Debian2Cached Path Relative Debian LinuxNov 21, 2024 Nov 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS a...Show more |
1Yitechnology 2Yi Home Yi Home Camera FirmwareNov 21, 2024 Nov 2, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can allocate unlimited memory, resulting in denial of service. A...Show more |
3Debian GlusterRedhat5Debian Linux Enterprise Linux ServerGlusterfs+2 moreNov 21, 2024 Nov 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode...Show more |
2Debian Redhat5Debian Linux Enterprise Linux ServerGluster File System+2 moreNov 21, 2024 Oct 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Glu...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Oct 31, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of memory when executing commands |
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have th...Show more |
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits. |
The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack...Show more |
1Qualcomm 9Sd 205 Firmware Sd 210 FirmwareSd 212 Firmware+6 moreNov 21, 2024 Oct 26, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 When FW tries to get random mac address generated from new SW RNG and ADC values read are constant then DUT get struck in loop while trying to get random ADC samples in Snapdragon Mobile in version SD 210/SD 212/SD 205,...Show more |
1Qualcomm 19Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+16 moreNov 21, 2024 Oct 23, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD...Show more |
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. T...Show more |
1Cisco 1Aironet Access Points Nov 21, 2024 Oct 17, 2018 N/A· v4 6.8 MEDIUM· v3 5.5 MEDIUM· v2 A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) conditio...Show more |
1Yokogawa 4Fcj Firmware Fcn 100 FirmwareFcn 500 Firmware+1 moreNov 21, 2024 Oct 12, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the...Show more |
A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust the private Internal routing interfaces (IRIs) next-hop limit. Once the...Show more |
A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system performance. Affected releases are Juniper Networks Junos OS: 12.1X...Show more |