CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,812)
page 29 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-54730 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2025 | Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function. | ||
| CVE-2025-21389 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-21330 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Windows Remote Desktop Services Denial of Service Vulnerability | ||
| CVE-2025-21300 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability | ||
| CVE-2025-21290 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21289 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21270 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21251 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21231 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | IP Helper Denial of Service Vulnerability | ||
| CVE-2025-21230 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21218 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2025-21207 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability | ||
| CVE-2024-57655 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2025 | An issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | ||
| CVE-2024-55605 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers,… | ||
| CVE-2024-56200 | Hig | 0.49 | 8.6 | 0.01 | Dec 19, 2024 | Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing remote files could allow attacks that could affect availability, such as by abnormally increasing the CPU usage of the server… | ||
| CVE-2024-11835 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2024 | Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | ||
| CVE-2024-49129 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | ||
| CVE-2024-49096 | Hig | 0.49 | 7.5 | 0.03 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2024-49075 | Hig | 0.49 | 7.5 | 0.03 | Dec 12, 2024 | Windows Remote Desktop Services Denial of Service Vulnerability | ||
| CVE-2024-48989 | Hig | 0.49 | 7.5 | 0.01 | Nov 13, 2024 | A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages. |
- risk 0.49cvss 7.5epss 0.01
Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.
- risk 0.49cvss 7.5epss 0.02
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Windows Remote Desktop Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
IP Helper Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Kerberos Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
An issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- risk 0.49cvss 7.5epss 0.01
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers,…
- risk 0.49cvss 8.6epss 0.01
Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing remote files could allow attacks that could affect availability, such as by abnormally increasing the CPU usage of the server…
- risk 0.49cvss 7.5epss 0.00
Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
- risk 0.49cvss 7.5epss 0.01
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Remote Desktop Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages.