CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 34 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-55605 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers,… | ||
| CVE-2024-56200 | Hig | 0.49 | 8.6 | 0.01 | Dec 19, 2024 | Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing remote files could allow attacks that could affect availability, such as by abnormally increasing the CPU usage of the server… | ||
| CVE-2024-11835 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2024 | Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1. | ||
| CVE-2024-49129 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | ||
| CVE-2024-49096 | Hig | 0.49 | 7.5 | 0.03 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2024-49075 | Hig | 0.49 | 7.5 | 0.03 | Dec 12, 2024 | Windows Remote Desktop Services Denial of Service Vulnerability | ||
| CVE-2024-48989 | Hig | 0.49 | 7.5 | 0.00 | Nov 13, 2024 | A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages. | ||
| CVE-2024-9409 | Hig | 0.49 | 7.5 | 0.01 | Nov 13, 2024 | CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network. | ||
| CVE-2024-10466 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2024 | By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. | ||
| CVE-2024-47497 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2024 | An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). An attacker can send specific HTTPS… | ||
| CVE-2024-7294 | Hig | 0.49 | 7.5 | 0.00 | Oct 9, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting. | ||
| CVE-2024-43575 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2024-43545 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | ||
| CVE-2024-43544 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | ||
| CVE-2024-43541 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | ||
| CVE-2024-43515 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | ||
| CVE-2024-43506 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | BranchCache Denial of Service Vulnerability | ||
| CVE-2024-38149 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | BranchCache Denial of Service Vulnerability | ||
| CVE-2024-8626 | Hig | 0.49 | 7.5 | 0.01 | Oct 8, 2024 | Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully… | ||
| CVE-2024-43789 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of… |
- risk 0.49cvss 7.5epss 0.01
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers,…
- risk 0.49cvss 8.6epss 0.01
Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing remote files could allow attacks that could affect availability, such as by abnormally increasing the CPU usage of the server…
- risk 0.49cvss 7.5epss 0.00
Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
- risk 0.49cvss 7.5epss 0.01
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Remote Desktop Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.00
A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages.
- risk 0.49cvss 7.5epss 0.01
CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.
- risk 0.49cvss 7.5epss 0.01
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
- risk 0.49cvss 7.5epss 0.01
An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). An attacker can send specific HTTPS…
- risk 0.49cvss 7.5epss 0.00
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
- risk 0.49cvss 7.5epss 0.02
Windows Hyper-V Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
BranchCache Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
BranchCache Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully…
- risk 0.49cvss 7.5epss 0.00
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of…