CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,128 vulnerabilities with CWE-400
CVE-2024-53299 MEDIUM
Apache Wicket 7.0.0-7.17.9 and 8.0.0-8.16.9 - Denial of Service via Request Handling
CVSS 6.5
CVE-2024-57724 MEDIUM
lunasvg 3.0.0 - Segmentation Violation in gray_record_cell
CVSS 6.5
CVE-2024-43763 MEDIUM
Android - Denial of Service in gatt_sr.cc build_read_multi_rsp
CVSS 6.5
CVE-2024-24424 HIGH
Magma <= 1.8.0 - Denial of Service via Crafted NAS Packet
CVSS 7.5
CVE-2024-50953 HIGH
XINJE XL5E-16T V3.7.2a - Denial of Service via Crafted Modbus Message
CVSS 7.5
CVE-2024-54730 HIGH
Flatnotes < 5.3.1 - Denial of Service via Image Upload Function
CVSS 7.5
CVE-2024-57655 HIGH
Virtuoso 7.2.11 - Denial of Service via Crafted SQL Statements
CVSS 7.5
CVE-2024-47239 MEDIUM
Dell PowerScale OneFS <9.9.0.0 - DoS
CVSS 6.5
CVE-2024-55605 HIGH
Suricata < 7.0.8 - Denial of Service via Large Input Buffer to Transform Functions
CVSS 7.5
CVE-2024-53647 MEDIUM
Trend Micro ID Security < 3.0 - Denial of Service via Unlimited Email Verification Requests
CVSS 6.5
CVE-2024-13058 MEDIUM
SoftIron HyperCloud <2.5.0 - Privilege Escalation
CVE-2024-56200 HIGH
Altair < v12.24Q4.1 - Unauthenticated Denial of Service via Image Proxy
CVSS 8.6
CVE-2024-12698 MEDIUM
Red Hat OpenShift Container Platform 4.18 - Uncontrolled Resource Consumption via Authenticated Streams
CVSS 6.5
CVE-2024-54677 MEDIUM
Apache Tomcat 8.5.0-8.5.100, 9.0.0.M1-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - DoS via Examples Web App
CVSS 5.3
CVE-2024-12601 MEDIUM
Calculated Fields Form <= 5.2.63 - Unauthenticated Denial of Service via CAPTCHA Image Dimensions
CVSS 5.3
CVE-2024-11835 HIGH
PlexTrac 1.61.3-2.8.1 - Denial of Service via WebSocket
CVSS 7.5
CVE-2024-12579 MEDIUM
Minify HTML <= 2.1.10 - Unauthenticated Regular Expression Denial of Service via Comment Processing
CVSS 5.3
CVE-2024-54113 MEDIUM
Process Residence - Info Disclosure
CVSS 6.5
CVE-2024-49129 HIGH
Windows Server 2012, 2016, 2019, 2022, 2025 Remote Desktop Gateway DoS
CVSS 7.5
CVE-2024-49096 HIGH
Microsoft Windows 10 1507-24H2 and Windows Server 2008-2012 - Denial of Service in Message Queuing
CVSS 7.5
CVE-2024-49075 HIGH
Windows Remote Desktop Services - Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2024-42426 MEDIUM
Dell PowerScale OneFS 9.5.0.x-9.8.0.x - Denial of Service via Uncontrolled Resource Consumption
CVSS 4.3
CVE-2024-12254 HIGH
CPython 3.12.0-3.12.8, 3.13.0-3.13.1, 3.14.0a1-3.14.0a2 - Resource Consumption in asyncio
CVSS 7.5
CVE-2024-11498 HIGH
libjxl < 0.8.4 - Stack Buffer Overflow via Crafted JPEG XL File
CVSS 7.5
CVE-2024-52804 HIGH
Tornado < 6.4.2 - Denial of Service via Malicious Cookie Header Parsing
CVSS 7.5
Details
Vulnerabilities 3,128
Exploit Likelihood High