CWE-400
3,601 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,601)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Powerdns3Authoritative Debian LinuxRecursorNov 21, 2024 Sep 11, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending...Show more |
2Debian Powerdns2Authoritative Debian LinuxNov 21, 2024 Sep 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If...Show more |
An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES when used with a 32 bi...Show more |
1Technicolor 1Tg588v Firmware Nov 21, 2024 Sep 6, 2018 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15...Show more |
7Canonical DebianF5+4 more51Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+48 moreJun 17, 2026 Sep 6, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending...Show more |
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. This issue can allow a remote attacker who...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Sep 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeated...Show more |
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host m...Show more |
2Dell Oracle13Application Testing Suite BsafeBsafe Crypto C+10 moreNov 21, 2024 Aug 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability whe...Show more |
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a Z...Show more |
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image s...Show more |
1Technicolor 1Tc8305c Firmware Nov 21, 2024 Aug 29, 2018 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 an...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Aug 29, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2...Show more |
2Canonical Xkbcommon3Libxkbcommon Ubuntu LinuxXkbcommonNov 21, 2024 Aug 25, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation. |
1Technicolor 1Tc7200.20 Firmware Nov 21, 2024 Aug 25, 2018 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: Technicolor denies that the described behavior is...Show more |
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability. An authenticated remote attacker can crash the HTTP server and in some circumstances reboot the system via a crafted HTTP POS...Show more |
An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of s...Show more |
In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are c...Show more |
1Symantec 1Encryption Management Server Nov 21, 2024 Aug 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a p...Show more |
An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making up a tuple. As indicated in section 7.7.3 "Operations on data structure...Show more |