CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,102 vulnerabilities with CWE-400
CVE-2025-53046 MEDIUM
Oracle ZFS Storage Appliance Kit 8.8 - Denial of Service in Analytics Component
CVSS 4.9
CVE-2025-53045 MEDIUM
MySQL Server 8.0.0-8.0.43, 8.4.0-8.4.6, 9.0.0-9.4.0 - Denial of Service in InnoDB
CVSS 4.9
CVE-2025-53044 MEDIUM
MySQL Server 8.0.0-8.0.43, 8.4.0-8.4.6, 9.0.0-9.4.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-53042 MEDIUM
MySQL Server 8.0.0-8.0.43, 8.4.0-8.4.6, 9.0.0-9.4.0 - Authenticated Denial of Service in Optimizer
CVSS 4.9
CVE-2025-53040 MEDIUM
MySQL Server 8.0.0-8.0.43, 8.4.0-8.4.6, 9.0.0-9.4.0 - Authenticated Denial of Service in Optimizer
CVSS 4.9
CVE-2025-60790 MEDIUM
ProcessWire CMS 3.0.246 - Authenticated Denial of Service via Language Support ZIP Upload
CVSS 6.5
CVE-2025-61303 CRITICAL
Hatching Triage Sandbox Windows 10 build 2004 and LTSC 2021 - Denial-of-Analysis via Recursive Child Process Spawning
CVSS 9.8
CVE-2025-61301 HIGH
CAPEv2 - Denial of Service via Oversized Behavior Data
CVSS 7.5
CVE-2025-26782 HIGH
Samsung Exynos and Modem Firmware - Denial of Service via RLC AM PDU Handling
CVSS 7.5
CVE-2025-59043 HIGH
OpenBao < 2.4.1 - Unauthenticated Denial of Service via JSON Deserialization Memory Exhaustion
CVSS 7.5
CVE-2025-33177 MEDIUM
NVIDIA Jetson/Linux & IGX - Memory Corruption
CVSS 5.5
CVE-2025-60536 HIGH
kafka-ui 0.6.0-0.7.2 - Denial of Service via Crafted Configuration File Upload
CVSS 7.5
CVE-2025-59502 HIGH
Windows Remote Procedure Call - Unauthenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2025-37148 MEDIUM
ArubaOS Multiple Versions - Unauthenticated DoS via Ethernet Frame Parsing
CVSS 6.5
CVE-2025-37139 MEDIUM
AOS Firmware - Privilege Escalation
CVSS 6.0
CVE-2025-11635 MEDIUM
Furbo 360 Dog Camera Firmware < 036 - Uncontrolled Resource Consumption via File Upload
CVSS 4.3
CVE-2025-61920 HIGH
Authlib < 1.6.5 - Uncontrolled Resource Consumption via Oversized JWS/JWT Segments
CVSS 7.5
CVE-2025-61919 HIGH
Rack < 2.2.20 - Denial of Service via Unbounded Form Parameter Memory Consumption
CVSS 7.5
CVE-2025-59975 HIGH
Juniper Junos Space <22.2R1 & 23.1-23.1R1 - DoS via HTTP API Flood
CVSS 7.5
CVE-2025-52961 MEDIUM
Juniper Junos OS Evolved DoS via CFM Traffic
CVSS 6.5
CVE-2025-61772 HIGH
Rack < 2.2.19 - Denial of Service via Unbounded Multipart Header Parsing
CVSS 7.5
CVE-2025-61771 HIGH
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Form Non-File Fields
CVSS 7.5
CVE-2025-61770 HIGH
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Preamble Buffering
CVSS 7.5
CVE-2025-11274 LOW
Open Asset Import Library Assimp 6.0.2 - Info Disclosure
CVSS 3.3
CVE-2025-52867 MEDIUM
Qsync Central 5.0.0.0-5.0.0.1 - Authenticated Denial of Service via Resource Consumption
CVSS 6.5
Details
Vulnerabilities 3,102
Exploit Likelihood High