CWE-400
3,601 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,601)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server...Show more |
1Apple 3Iphone Os Mac Os XWatchosNov 21, 2024 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote...Show more |
2Debian Redhat2Debian Linux LibvirtNov 21, 2024 Mar 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent. |
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) ca...Show more |
1Redhat 1Jboss Wildfly Application Server Nov 21, 2024 Mar 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that th...Show more |
1Huawei 10Dp300 Firmware Ecns210 Td FirmwareEspace U1981 Firmware+7 moreNov 21, 2024 Mar 9, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Huawei DP300 V500R002C00, NIP6600 V500R001C00, V500R001C20, V500R001C30, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, TE60 V100R001C01, V100R001C10, V100R003C00, V500R002C00, V600R006C00, TP3106 V100R001C06,...Show more |
2Debian Libming2Debian Linux LibmingJun 17, 2026 Mar 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service via a crafted file. |
2Apache Redhat4Activemq Artemis ArtemisHornetq+1 moreJun 15, 2026 Mar 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memor...Show more |
4Canonical DebianMemcached+1 more4Debian Linux MemcachedOpenstack+1 moreNov 21, 2024 Mar 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via networ...Show more |
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. |
index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string. |
3Canonical DebianDovecot3Debian Linux DovecotUbuntu LinuxNov 21, 2024 Mar 2, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart. |
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Mar 1, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Mar 1, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) f...Show more |
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing. |
An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer. |
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthr...Show more |
1Huawei 2Te60 Firmware Viewpoint 9030 FirmwareNov 21, 2024 Feb 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Light Directory Access Protocol (LDAP) clients of Huawei TE60 with software V600R006C00, ViewPoint 9030 with software V100R011C02, V100R011C03 have a resource management errors vulnerability. An unauthenticated, remo...Show more |
1Huawei 6Dp300 Firmware Secospace Usg6300 FirmwareSecospace Usg6500 Firmware+3 moreNov 21, 2024 Feb 15, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V500R001C00, V500R001C20, V500R001C3...Show more |