CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 33 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20058 | Hig | 0.49 | 7.5 | 0.00 | Feb 5, 2025 | When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | ||
| CVE-2023-37022 | Hig | 0.49 | 7.5 | 0.01 | Jan 22, 2025 | Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service. | ||
| CVE-2023-37014 | Hig | 0.49 | 7.5 | 0.01 | Jan 22, 2025 | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting… | ||
| CVE-2024-24424 | Hig | 0.49 | 7.5 | 0.00 | Jan 21, 2025 | A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | ||
| CVE-2025-21549 | Hig | 0.49 | 7.5 | 0.01 | Jan 21, 2025 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle… | ||
| CVE-2025-21545 | Hig | 0.49 | 7.5 | 0.01 | Jan 21, 2025 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | ||
| CVE-2024-50953 | Hig | 0.49 | 7.5 | 0.00 | Jan 15, 2025 | An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message. | ||
| CVE-2024-54730 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2025 | Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function. | ||
| CVE-2025-21389 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-21330 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Windows Remote Desktop Services Denial of Service Vulnerability | ||
| CVE-2025-21300 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability | ||
| CVE-2025-21290 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21289 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21270 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21251 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21231 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | IP Helper Denial of Service Vulnerability | ||
| CVE-2025-21230 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21218 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2025 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2025-21207 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability | ||
| CVE-2024-57655 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2025 | An issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. |
- risk 0.49cvss 7.5epss 0.00
When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- risk 0.49cvss 7.5epss 0.01
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.
- risk 0.49cvss 7.5epss 0.01
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…
- risk 0.49cvss 7.5epss 0.00
A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle…
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
- risk 0.49cvss 7.5epss 0.00
An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.
- risk 0.49cvss 7.5epss 0.01
Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.
- risk 0.49cvss 7.5epss 0.02
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Windows Remote Desktop Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
IP Helper Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Kerberos Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
An issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.