CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,129 vulnerabilities with CWE-400
CVE-2025-50100 LOW
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Uncontrolled Resource Consumption in Thread Pooling
CVSS 2.2
CVE-2025-50099 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-50098 LOW
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Partial Denial of Service in Server Optimizer
CVSS 2.7
CVE-2025-50097 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Denial of Service in Server Security Encryption
CVSS 4.9
CVE-2025-50096 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in InnoDB
CVSS 4.4
CVE-2025-50095 MEDIUM
MySQL 9.0.0-9.3.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2025-50094 MEDIUM
MySQL 8.0.42, 8.4.5, 9.3.0 - Denial of Service in Server DDL
CVSS 4.9
CVE-2025-50093 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Denial of Service in Server DDL
CVSS 4.9
CVE-2025-50092 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-50091 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2025-50089 MEDIUM
MySQL 9.0.0-9.1.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2025-50088 MEDIUM
MySQL 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-50083 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Denial of Service in Server Optimizer
CVSS 6.5
CVE-2025-50082 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Denial of Service in Server Optimizer
CVSS 6.5
CVE-2025-50080 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in Stored Procedure
CVSS 4.9
CVE-2025-50079 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2025-50078 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Denial of Service in Server: DML
CVSS 6.5
CVE-2025-50077 MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2025-50076 MEDIUM
MySQL 8.0.0-8.0.25 - Denial of Service in Server: DML
CVSS 6.5
CVE-2025-30753 MEDIUM
Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 - Denial of Service via HTTP
CVSS 6.5
CVE-2025-30752 LOW
Oracle GraalVM for JDK 24.0.1 - Unauthenticated Partial Denial of Service in Compiler
CVSS 3.7
CVE-2025-53893 MEDIUM
filebrowser 2.38.0 - Authenticated Denial of Service via File Read Endpoint
CVSS 6.5
CVE-2025-48795 MEDIUM
Apache CXF < 3.5.11, 3.6.6, 4.0.7, 4.1.1 - Denial of Service via Temporary File Logging
CVSS 5.6
CVE-2025-7579 MEDIUM
chinese-poetry 0.1 - Info Disclosure
CVSS 4.3
CVE-2025-24294 HIGH
Ruby resolv < 0.2.3, 0.2-0.2.2, 0.3.0, 0.6-0.6.1 - Denial of Service via DNS Packet Decompression
CVSS 7.5
Details
Vulnerabilities 3,129
Exploit Likelihood High