CWE-400
3,601 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,601)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Huawei Smartphones with software LON-L29DC721B186 have a denial of service vulnerability. An attacker could make an loop exit condition that cannot be reached by sending the crafted 3GPP message. Successful exploit could...Show more |
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is neede...Show more |
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of req...Show more |
The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sandbox, or by using a large amount of disk...Show more |
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string. |
4Canonical DebianOracle+1 more4Debian Linux GeorasterOpenjpeg+1 moreJun 17, 2026 Feb 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. |
2Apport Project Canonical2Apport Ubuntu LinuxNov 3, 2025 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resour...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhau...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion...Show more |
A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from accepting new connections. |
In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf...Show more |
2Ibm Lenova42Bladecenter Hs22 Firmware Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 moreNov 21, 2024 Jan 26, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a hi...Show more |
3Canonical DebianDovecot3Debian Linux DovecotUbuntu LinuxNov 21, 2024 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration whe...Show more |
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. |
2Debian Redhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreJun 17, 2026 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply. |
1Siemens 1Telecontrol Server Basic Nov 21, 2024 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver (port 80/tcp or 443/tcp) could cause a Denial-of-Service condition on the web se...Show more |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxJun 17, 2026 Jan 19, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This...Show more |
1Cisco 1Unified Computing System Central Software Nov 21, 2024 Jan 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted de...Show more |
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This c...Show more |
1Cisco 1Unified Customer Voice Portal Nov 21, 2024 Jan 18, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerab...Show more |