CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,811)
page 2 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-20004 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2022 | A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. This affects iSCSI SAN… | ||
| CVE-2021-1275 | Cri | 0.64 | 9.8 | 0.02 | May 6, 2021 | Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the… | ||
| CVE-2017-9104 | Cri | 0.64 | 9.8 | 0.02 | Jun 18, 2020 | An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered. | ||
| CVE-2019-10750 | Cri | 0.64 | 9.8 | 0.02 | Aug 23, 2019 | deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload. | ||
| CVE-2019-2259 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2019 | Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2018-11936 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2019 | Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads to out of bound memory access. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon… | ||
| CVE-2019-10952 | Cri | 0.64 | 9.8 | 0.10 | May 1, 2019 | An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact… | ||
| CVE-2018-19282 | Cri | 0.64 | 9.8 | 0.06 | Apr 4, 2019 | Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a way that it does not accept new… | ||
| CVE-2018-16491 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2019 | A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype. | ||
| CVE-2018-16489 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2019 | A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions. | ||
| CVE-2018-16486 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2019 | A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype. | ||
| CVE-2017-1000378 | Cri | 0.64 | 9.8 | 0.04 | Jun 19, 2017 | The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack… | ||
| CVE-2017-9119 | Cri | 0.64 | 9.8 | 0.04 | May 21, 2017 | The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures. | ||
| CVE-2023-50707 | Cri | 0.62 | 9.6 | 0.01 | Dec 20, 2023 | Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device. | ||
| CVE-2023-38180 | Hig | 0.62 | 7.5 | 0.15 | KEV | Aug 8, 2023 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2026-28318 | Hig | 0.61 | 7.5 | 0.08 | KEV | Jun 4, 2026 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the… | |
| CVE-2026-22542 | — | Cri | 0.60 | — | 0.00 | Jan 7, 2026 | An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service. | |
| CVE-2026-22540 | — | Cri | 0.60 | — | 0.00 | Jan 7, 2026 | The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly. | |
| CVE-2025-64388 | — | Cri | 0.60 | — | 0.00 | Oct 31, 2025 | Denial of service of the web server through specific requests to this protocol | |
| CVE-2024-6036 | Cri | 0.60 | 9.1 | 0.11 | Jul 10, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unrestricted server restart capability can severely disrupt service availability,… |
- risk 0.64cvss 9.8epss 0.01
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. This affects iSCSI SAN…
- risk 0.64cvss 9.8epss 0.02
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
- risk 0.64cvss 9.8epss 0.02
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
- risk 0.64cvss 9.8epss 0.01
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.64cvss 9.8epss 0.01
Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads to out of bound memory access. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…
- risk 0.64cvss 9.8epss 0.10
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact…
- risk 0.64cvss 9.8epss 0.06
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a way that it does not accept new…
- risk 0.64cvss 9.8epss 0.02
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
- risk 0.64cvss 9.8epss 0.02
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
- risk 0.64cvss 9.8epss 0.01
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
- risk 0.64cvss 9.8epss 0.04
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack…
- risk 0.64cvss 9.8epss 0.04
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
- risk 0.62cvss 9.6epss 0.01
Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.
- risk 0.62cvss 7.5epss 0.15
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.61cvss 7.5epss 0.08
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the…
- risk 0.60cvss —epss 0.00
An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.
- risk 0.60cvss —epss 0.00
The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.
- risk 0.60cvss —epss 0.00
Denial of service of the web server through specific requests to this protocol
- risk 0.60cvss 9.1epss 0.11
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unrestricted server restart capability can severely disrupt service availability,…