← Back
CWE-400

3,601 CVEs • Abstraction: Class • Likelihood of Exploit: High

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

JSON object

Loading...

CVEs (3,601)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Graphicsmagick
1Graphicsmagick
May 13, 2026
Jul 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().
1Schneider Electric
15Bmxnoc0401 Firmware
Bmxnoe0100 FirmwareBmxnoe0110 Firmware+12 more
May 13, 2026
Jun 30, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H,...Show more
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.Show less
1Openvpn
1Openvpn
May 13, 2026
Jun 27, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().
1Trihedral
1Vtscada
May 13, 2026
Jun 21, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an attacker, which can be...Show more
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an attacker, which can be used to consume more resources than are available.Show less
1Audiocoding
1Freeware Advanced Audio Coder
May 13, 2026
Jun 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.
1Netbsd
1Netbsd
May 13, 2026
Jun 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consum...Show more
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.Show less
1Openbsd
1Openbsd
May 13, 2026
Jun 19, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consu...Show more
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.Show less
1Apache
1Ws Xmlrpc
May 13, 2026
Jun 6, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
1Apple
1Mac Os X
May 13, 2026
May 22, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (resour...Show more
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (resource consumption) via a crafted app.Show less
1Cisco
2Firepower Threat Defense
Secure Firewall Threat Defense
Aug 11, 2026
May 22, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (Do...Show more
A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain TCP packets by the affected software. An attacker could exploit this vulnerability by sending a flood of crafted TCP packets to an affected device. A successful exploit could allow the attacker to cause a DoS condition. The success of an exploit is dependent on how an administrator has configured logging for SSL policies for a device. This vulnerability affects Cisco FirePOWER System Software that is configured to log connections by using SSL policy default actions. Cisco Bug IDs: CSCvd07072.Show less
2Netapp
Php
3Clustered Data Ontap
PhpStorage Automation Store
May 13, 2026
May 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted...Show more
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.Show less
1Phoenix Contact Gmbh
1Mguard Firmware
May 13, 2026
May 19, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the device's availability by performing multiple initial VPN requests.
1Mikrotik
1Routeros
May 13, 2026
May 18, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router fro...Show more
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.Show less
1Siemens
79Dk Standard Ethernet Controller Firmware
Ek Ertec 200 Pn Io FirmwareEk Ertec 200p Pn Io Firmware+76 more
May 13, 2026
May 11, 2017
7.1 HIGH· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PRO...Show more
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.Show less
1Siemens
93Dk Standard Ethernet Controller Firmware
Ek Ertec 200 Pn Io FirmwareEk Ertec 200p Pn Io Firmware+90 more
May 13, 2026
May 11, 2017
7.1 HIGH· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interf...Show more
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.Show less
1Rockwellautomation
2Compactlogix 5380 Firmware
Controllogix 5580 Firmware
May 13, 2026
May 6, 2017
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogi...Show more
A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vulnerability may allow an attacker to cause a denial of service condition by sending a series of specific CIP-based commands to the controller.Show less
1Entropymine
1Imageworsener
May 13, 2026
Apr 29, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted image.
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by c...Show more
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by consuming TCP and UDP ports which are normally reserved for other system services.Show less
1Opendaylight
1Opendaylight
May 13, 2026
Apr 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.
1Opendaylight
1Opendaylight
May 13, 2026
Apr 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communica...Show more
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight versions 3.3 (Lithium-SR3), 3.4 (Lithium-SR4), 4.0 (Beryllium), 4.1 (Beryllium-SR1), 4.2 (Beryllium-SR2), and 4.4 (Beryllium-SR4) are affected by this flaw. Java version is openjdk version 1.8.0_91.Show less