CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,102 vulnerabilities with CWE-400
CVE-2025-48576 MEDIUM
Android - Denial of Service via Resource Exhaustion in NotificationManagerService
CVSS 5.5
CVE-2025-65637 HIGH
logrus < 1.8.3 - Denial of Service via Large Single-Line Payload
CVSS 7.5
CVE-2025-66453 HIGH
Rhino <1.8.1, <1.7.15.1, <1.7.14.1 - DoS
CVSS 7.5
CVE-2025-66303 MEDIUM
Grav < 1.8.0-beta.27 - Denial of Service via Scheduled_at Parameter
CVSS 4.9
CVE-2025-13837 MEDIUM
Python < 3.13.10 - Denial of Service via plistlib Malicious File Size Handling
CVSS 5.5
CVE-2025-13836 HIGH
Python < 3.13.11 - Uncontrolled Resource Consumption via HTTP Response Content-Length
CVSS 7.5
CVE-2025-58436 MEDIUM
OpenPrinting CUPS < 2.4.15 - Denial of Service via Slow Client Message Handling
CVSS 5.1
CVE-2025-66019 MEDIUM
pypdf < 6.4.0 - Uncontrolled Resource Consumption via LZWDecode Filter
CVE-2025-51741 HIGH
Echo 2.2-2.3 - Unauthenticated Denial of Service via Email Verification Endpoint
CVSS 7.5
CVE-2025-13466 MEDIUM
body-parser 2.2.0 - Denial of Service via URL-Encoded Parameter Flood
CVE-2025-60638 HIGH
free5gc 4.0.0-4.0.1 - Denial of Service via Nnssf_NSSAIAvailability API
CVSS 7.5
CVE-2025-65947 HIGH
thread-amount <0.2.2 - Resource Leak
CVE-2025-55128 MEDIUM
Revive Adserver 6.0.0-6.0.3 - Uncontrolled Resource Consumption in userlog-index.php
CVSS 6.5
CVE-2025-37161 HIGH
ArubaOS < 10.7.2.0 - Unauthenticated Denial of Service via Web Management Interface
CVSS 7.5
CVE-2025-55796 HIGH
openml/openml.org v2.0.20241110 - Info Disclosure
CVSS 7.5
CVE-2025-6599 MEDIUM
Zyxel DX3301-T0 <5.50(ABVY.6.3)C0 - DoS
CVSS 5.3
CVE-2025-11681 MEDIUM
M-Files Server < 25.11.15392.1, < 25.2 LTS SR2, < 25.8 LTS SR2 - Authenticated Denial of Service
CVSS 6.5
CVE-2025-63811 HIGH
dvsekhvalnov jose2go 1.5.0-1.7.0 - Denial of Service via Crafted JWE Token
CVSS 7.5
CVE-2025-27249 MEDIUM
Gaudi software < 1.21.0 - Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-63288 HIGH
Open5GS 2.7.6 - Denial of Service via Abnormal NGSetupRequest Message
CVSS 7.5
CVE-2025-63560 HIGH
KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware 1.20.0006 - DoS via Systemctrl API
CVSS 7.5
CVE-2025-60753 MEDIUM
libarchive < 3.8.1 - Denial of Service via Crafted Substitution Rules
CVSS 5.5
CVE-2025-49494 HIGH
Samsung Exynos and Modem 5123 Firmware - Denial of Service via 5G NRMM Packet Mishandling
CVSS 7.5
CVE-2025-43462 HIGH
iPadOS < 26.1 - Denial of Service via Memory Corruption
CVSS 7.5
CVE-2025-63561 HIGH
Summer Pearl Group Vacation Rental Management Platform <1.0.2 - DoS
CVSS 7.5
Details
Vulnerabilities 3,102
Exploit Likelihood High