CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,129 vulnerabilities with CWE-400
CVE-2025-26472 MEDIUM
Intel(R) Tiber(TM) Edge Platform <24.11.1 - DoS
CVSS 5.7
CVE-2025-40766 MEDIUM
SINEC Traffic Analyzer < 3.0 - Denial of Service via Uncontrolled Docker Resource Consumption
CVSS 5.5
CVE-2025-55152 MEDIUM
oak < 17.1.6 - Denial of Service via Inefficient Regular Expression in Header Parsing
CVSS 5.3
CVE-2025-54884 HIGH
Vision UI < 1.5.0 - Denial of Service via Security-Kit Secure ID Generation
CVE-2025-8537 LOW
Bento4 < 1.6.0-641 - Uncontrolled Resource Consumption in AP4_DataBuffer::SetDataSize
CVSS 3.7
CVE-2025-54796 HIGH
copyparty < 1.18.9 - Denial of Service via Filter Parameter Regular Expression
CVSS 7.5
CVE-2025-53012 HIGH
MaterialX 1.39.2 - Denial of Service via Nested Import Chain Depth Exhaustion
CVSS 7.5
CVE-2025-54575 MEDIUM
SixLabors.ImageSharp < 2.1.11 and 3.0.0-3.1.10 - Denial of Service via Malformed GIF Comment Extension Block
CVSS 5.3
CVE-2025-54572 MEDIUM
ruby-saml < 1.18.1 - Denial of Service via Base64 Validation Bypass
CVE-2025-43235 MEDIUM
macOS < 15.6 - Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-43193 CRITICAL
macOS < 13.7.7, < 14.7.7, < 15.6 - Denial of Service
CVSS 9.8
CVE-2025-8262 MEDIUM
yarnpkg Yarn <1.22.22 - Info Disclosure
CVSS 4.3
CVE-2025-46171 MEDIUM
vBulletin 3.8.7 - Authenticated Denial of Service via Buddy List Processing
CVSS 5.4
CVE-2025-53538 HIGH
Suricata <7.0.10 and <8.0.0-rc1 - Memory Corruption
CVSS 7.5
CVE-2025-44653 HIGH
H3C GR2200 MiniGR1A0V100R016 - Denial of Service via USERLIMIT_GLOBAL Misconfiguration
CVSS 7.5
CVE-2025-44651 HIGH
TRENDnet TPL-430AP FW1.0 - Denial of Service via USERLIMIT_GLOBAL Misconfiguration
CVSS 7.5
CVE-2025-44650 HIGH
Netgear R7000 and EAX80 Firmware - Denial of Service via Unlimited User Connections
CVSS 7.5
CVE-2025-41677 MEDIUM
mbconnectline mbnet.mini_firmware < 2.3.3 - Denial of Service via Send-Mail Action
CVSS 4.9
CVE-2025-41676 MEDIUM
mbnet.mini_firmware < 2.3.3 - Unauthenticated Denial of Service via Crafted POST Requests to send-sms Action
CVSS 4.9
CVE-2025-50057 MEDIUM
RSFiles! component for Joomla 1.16.3-1.17.7 - Unauthenticated Denial of Service via Search Feature
CVE-2025-53023 MEDIUM
Oracle MySQL Server 8.0.0-8.0.42 - Authenticated Denial of Service in Replication Component
CVSS 4.9
CVE-2025-50104 LOW
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Partial Denial of Service in Server DDL
CVSS 2.7
CVE-2025-50103 MEDIUM
MySQL 9.0.0-9.3.0 - Authenticated Denial of Service in LDAP Auth Component
CVSS 4.4
CVE-2025-50102 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2025-50101 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
Details
Vulnerabilities 3,129
Exploit Likelihood High