CWE-400
3,262 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,262)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLinux+1 more6Debian Linux Linux Enterprise DesktopLinux Enterprise High Availability Extension+3 moreApr 29, 2026 May 17, 2012 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple proce...Show more |
The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management. |
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG bef...Show more |
Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of database usage. |
MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU c...Show more |
The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a denial of service (CPU...Show more |
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input...Show more |
The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large number of LLDP Management Address (MA) TLVs, which allows remote attackers to cause a denial of service (device crash) v...Show more |
4Canonical DebianLinux+1 more5Debian Linux Enterprise LinuxEnterprise Mrg+2 moreApr 29, 2026 Oct 10, 2011 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service...Show more |
2Apache Redhat2Http Server Jboss Enterprise Web ServerApr 29, 2026 Sep 20, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend...Show more |
4Apache CanonicalOpensuse+1 more5Http Server Linux Enterprise ServerLinux Enterprise Software Development Kit+2 moreApr 29, 2026 Aug 29, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses mul...Show more |
2Linux Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreApr 29, 2026 Jul 28, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service...Show more |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 May 26, 2011 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount...Show more |
3Linux RedhatVmware3Enterprise Linux EsxLinux KernelApr 29, 2026 May 26, 2011 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service (memory consumption) by se...Show more |
3Linux RedhatSuse6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 29, 2026 Apr 4, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted applica...Show more |
fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a den...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLinux Enterprise Server+3 moreApr 29, 2026 Mar 2, 2011 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT com...Show more |
mm/huge_memory.c in the Linux kernel before 2.6.38-rc5 does not prevent creation of a transparent huge page (THP) during the existence of a temporary stack for an exec system call, which allows local users to cause a den...Show more |
Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack vectors. |
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service...Show more |