CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,812)
page 30 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-9409 | Hig | 0.49 | 7.5 | 0.01 | Nov 13, 2024 | CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network. | ||
| CVE-2024-10466 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2024 | By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. | ||
| CVE-2024-47497 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2024 | An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). An attacker can send specific HTTPS… | ||
| CVE-2024-7294 | Hig | 0.49 | 7.5 | 0.00 | Oct 9, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting. | ||
| CVE-2024-43575 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2024-43545 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | ||
| CVE-2024-43544 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | ||
| CVE-2024-43541 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | ||
| CVE-2024-43515 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | ||
| CVE-2024-43506 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | BranchCache Denial of Service Vulnerability | ||
| CVE-2024-38149 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | BranchCache Denial of Service Vulnerability | ||
| CVE-2024-8626 | Hig | 0.49 | 7.5 | 0.01 | Oct 8, 2024 | Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully… | ||
| CVE-2024-43789 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of… | ||
| CVE-2024-47850 | Hig | 0.49 | 7.5 | 0.01 | Oct 4, 2024 | CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be… | ||
| CVE-2024-8451 | Hig | 0.49 | 7.5 | 0.01 | Sep 30, 2024 | Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the… | ||
| CVE-2024-37125 | Hig | 0.49 | 7.5 | 0.00 | Sep 26, 2024 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to a denial of service. | ||
| CVE-2024-31146 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2024 | When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually cannot really be guaranteed without knowing internals of any of the involved guests. Therefore such a configuration… | ||
| CVE-2024-31145 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2024 | Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise… | ||
| CVE-2023-28451 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2024 | An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing DoS (denial of service) for normal resolution. The effects of an exploit would be widespread and… | ||
| CVE-2024-27874 | Hig | 0.49 | 7.5 | 0.01 | Sep 17, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to cause a denial-of-service. |
- risk 0.49cvss 7.5epss 0.01
CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.
- risk 0.49cvss 7.5epss 0.01
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
- risk 0.49cvss 7.5epss 0.01
An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). An attacker can send specific HTTPS…
- risk 0.49cvss 7.5epss 0.00
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
- risk 0.49cvss 7.5epss 0.02
Windows Hyper-V Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
BranchCache Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
BranchCache Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully…
- risk 0.49cvss 7.5epss 0.00
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of…
- risk 0.49cvss 7.5epss 0.01
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be…
- risk 0.49cvss 7.5epss 0.01
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the…
- risk 0.49cvss 7.5epss 0.00
Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to a denial of service.
- risk 0.49cvss 7.5epss 0.00
When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually cannot really be guaranteed without knowing internals of any of the involved guests. Therefore such a configuration…
- risk 0.49cvss 7.5epss 0.00
Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing DoS (denial of service) for normal resolution. The effects of an exploit would be widespread and…
- risk 0.49cvss 7.5epss 0.01
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to cause a denial-of-service.