CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,161)
page 124 of 209| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-47329 | Med | 0.40 | 6.2 | 0.00 | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix resource leak in case of probe failure The driver doesn't clean up all the allocated resources properly when scsi_add_host(), megasas_start_aen() function fails during the PCI device… | ||
| CVE-2024-1014 | Med | 0.40 | 6.2 | 0.01 | Jan 29, 2024 | Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets. | ||
| CVE-2023-36042 | Med | 0.40 | 6.2 | 0.01 | Nov 14, 2023 | Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-45167 | Med | 0.40 | 6.2 | 0.00 | Nov 10, 2023 | IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965. | ||
| CVE-2023-27484 | Med | 0.40 | 6.2 | 0.01 | Mar 9, 2023 | crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. In affected versions an already highly privileged user able to create or update Compositions can specify an arbitrarily high index in a patch's `ToFieldPath`,… | ||
| CVE-2022-4816 | Med | 0.40 | 6.2 | 0.00 | Jan 23, 2023 | A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application. | ||
| CVE-2021-32821 | Med | 0.40 | 6.2 | 0.01 | Jan 3, 2023 | MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at… | ||
| CVE-2022-39164 | Med | 0.40 | 6.2 | 0.00 | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181. | ||
| CVE-2022-39165 | Med | 0.40 | 6.2 | 0.00 | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 235183. | ||
| CVE-2022-22101 | Med | 0.40 | 6.2 | 0.00 | Sep 2, 2022 | Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto | ||
| CVE-2022-35776 | Med | 0.40 | 6.2 | 0.01 | Aug 9, 2022 | Azure Site Recovery Denial of Service Vulnerability | ||
| CVE-2021-43933 | Med | 0.40 | 6.1 | 0.01 | Apr 20, 2022 | The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources. | ||
| CVE-2020-27223 | Med | 0.40 | 5.2 | 0.78 | Feb 26, 2021 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU… | ||
| CVE-2020-3479 | Med | 0.40 | 6.1 | 0.01 | Sep 24, 2020 | A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service… | ||
| CVE-2018-16845 | Med | 0.40 | 6.1 | 0.10 | Nov 7, 2018 | nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.… | ||
| CVE-2017-15529 | Med | 0.40 | 6.2 | 0.00 | Dec 13, 2017 | Prior to 4.4.1.10, the Norton Family Android App can be susceptible to a Denial of Service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular device unavailable to its intended user by temporarily or indefinitely disrupting… | ||
| CVE-2016-9039 | Med | 0.40 | 6.2 | 0.01 | Jan 31, 2017 | An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly… | ||
| CVE-2026-68904 | Hig | 0.39 | 7.0 | 0.00 | Sep 16, 2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated reconnection cycle when an OPC UA server's clock skew causes BadInvalidTimestamp responses.… | ||
| CVE-2026-76821 | Hig | 0.39 | — | 0.00 | Sep 15, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260706.0, the JSON ingestion mapper's extractWithRegexp formula function compiled a user-supplied regular expression with the JavaScript RegExp engine in… | ||
| CVE-2026-49249 | Hig | 0.39 | — | 0.00 | Sep 2, 2026 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of the user-supplied request body via… |
- risk 0.40cvss 6.2epss 0.00
In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix resource leak in case of probe failure The driver doesn't clean up all the allocated resources properly when scsi_add_host(), megasas_start_aen() function fails during the PCI device…
- risk 0.40cvss 6.2epss 0.01
Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets.
- risk 0.40cvss 6.2epss 0.01
Visual Studio Denial of Service Vulnerability
- risk 0.40cvss 6.2epss 0.00
IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965.
- risk 0.40cvss 6.2epss 0.01
crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. In affected versions an already highly privileged user able to create or update Compositions can specify an arbitrarily high index in a patch's `ToFieldPath`,…
- risk 0.40cvss 6.2epss 0.00
A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.
- risk 0.40cvss 6.2epss 0.01
MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at…
- risk 0.40cvss 6.2epss 0.00
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.
- risk 0.40cvss 6.2epss 0.00
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 235183.
- risk 0.40cvss 6.2epss 0.00
Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto
- risk 0.40cvss 6.2epss 0.01
Azure Site Recovery Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.01
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources.
- risk 0.40cvss 5.2epss 0.78
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU…
- risk 0.40cvss 6.1epss 0.01
A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service…
- risk 0.40cvss 6.1epss 0.10
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.…
- risk 0.40cvss 6.2epss 0.00
Prior to 4.4.1.10, the Norton Family Android App can be susceptible to a Denial of Service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular device unavailable to its intended user by temporarily or indefinitely disrupting…
- risk 0.40cvss 6.2epss 0.01
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly…
- risk 0.39cvss 7.0epss 0.00
node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated reconnection cycle when an OPC UA server's clock skew causes BadInvalidTimestamp responses.…
- risk 0.39cvss —epss 0.00
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260706.0, the JSON ingestion mapper's extractWithRegexp formula function compiled a user-supplied regular expression with the JavaScript RegExp engine in…
- risk 0.39cvss —epss 0.00
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of the user-supplied request body via…