CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,102 vulnerabilities with CWE-400
CVE-2025-9341 MEDIUM
Bouncy Castle for Java FIPS <2.1.0 - Excessive Allocation
CVE-2025-57751 HIGH
pyload-ng < 0.5.0b3.dev92 - Denial of Service via Unverified jk Parameter
CVE-2025-55521 MEDIUM
Akaunting < 3.1.19 - Authenticated Denial of Service via Localisation Settings
CVSS 6.5
CVE-2025-9308 LOW
yarnpkg Yarn <1.22.22 - Info Disclosure
CVSS 3.3
CVE-2025-48956 HIGH
vLLM 0.1.0-0.10.1.0 - Unauthenticated Denial of Service via Large HTTP Header
CVSS 7.5
CVE-2025-5115 HIGH
Eclipse Jetty <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2 - Resource Exhaustion via HTTP/2 RST_STREAM
CVSS 7.5
CVE-2025-8449 MEDIUM
Schneider Electric EcoStruxure BMS - Authenticated Denial of Service
CVE-2025-9182 HIGH
Firefox < 142.0 and 140.2-140.* - Denial of Service in WebRender Graphics Component
CVSS 7.5
CVE-2025-55029 HIGH
Firefox < 142.0 - Denial of Service via Popup Blocker Bypass
CVSS 7.5
CVE-2025-55028 MEDIUM
Firefox < 142.0 - Denial of Service via Repetitive JavaScript Alerts
CVSS 6.5
CVE-2025-55588 HIGH
TOTOLINK A3002R v4.0.0-B20230531.1404 - DoS
CVSS 7.5
CVE-2025-55587 HIGH
TOTOLINK A3002R v4.0.0-B20230531.1404 - DoS
CVSS 7.5
CVE-2025-55586 HIGH
TOTOLINK A3002R v4.0.0-B20230531.1404 - DoS
CVSS 7.5
CVE-2025-9092 LOW
Bouncy Castle for Java <2.1.0.0 - Uncontrolled Resource Consumption
CVE-2025-38501 HIGH
Linux Kernel - Denial of Service via Repeated ksmbd Connections from Same IP
CVSS 7.5
CVE-2025-50861 MEDIUM
Lotus Cars Android app 1.2.8 - SSRF
CVSS 6.5
CVE-2025-54472 HIGH
Apache bRPC < 1.14.1 - Denial of Service via Redis Protocol Parser Memory Allocation
CVSS 7.5
CVE-2025-55197 HIGH
pypdf < 6.0.0 - Denial of Service via FlateDecode Filter RAM Exhaustion
CVSS 7.5
CVE-2025-50615 HIGH
Netis WF2880 v2.1.40207 - Buffer Overflow
CVSS 7.5
CVE-2025-53722 HIGH
Windows Remote Desktop Services - DoS
CVSS 7.5
CVE-2025-27576 LOW
Intel(R) Tiber(TM) Edge Platform <24.11.1 - DoS
CVSS 2.9
CVE-2025-27250 LOW
Intel(R) Tiber(TM) Edge Platform <24.11.1 - DoS
CVSS 3.5
CVE-2025-26863 LOW
Intel 700 Series Ethernet <2.28.5 - DoS
CVSS 3.8
CVE-2025-26697 LOW
Intel 700 Series Ethernet <2.28.5 - DoS
CVSS 3.3
CVE-2025-26472 MEDIUM
Intel(R) Tiber(TM) Edge Platform <24.11.1 - DoS
CVSS 5.7
Details
Vulnerabilities 3,102
Exploit Likelihood High