CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,128 vulnerabilities with CWE-400
CVE-2024-42397 MEDIUM
AP Certificate Management daemon - DoS
CVSS 5.3
CVE-2024-30170 CRITICAL
PrivX 22.0-33.0 - Data Exfiltration and Denial of Service via REST API
CVSS 9.1
CVE-2024-3056 HIGH
Podman < 5.2.0 - Denial of Service via IPC Resource Exhaustion
CVSS 7.7
CVE-2024-41946 MEDIUM
REXML < 3.3.3 - Denial of Service via Entity Expansion in SAX2 or Pull Parser
CVSS 5.3
CVE-2024-41123 MEDIUM
REXML < 3.2.7 and 3.3.0-3.3.2 - Denial of Service via Malformed XML Parsing
CVSS 5.3
CVE-2024-37281 MEDIUM
Kibana 7.0.0-7.17.23 - Denial of Service via Maliciously Crafted Requests
CVSS 6.5
CVE-2024-37299 MEDIUM
Discourse < 3.2.5 - Denial of Service via Long Tag Group Name
CVSS 4.9
CVE-2024-27862 LOW
macOS Sonoma <14.6 - Info Disclosure
CVSS 2.4
CVE-2024-41818 HIGH
fast-xml-parser >=4.3.5 <4.4.1 - Uncontrolled Resource Consumption via ReDOS in Currency Parser
CVSS 7.5
CVE-2024-40575 MEDIUM
Huawei Technologies opengauss <7.3.0 - DoS
CVSS 5.5
CVE-2024-3297 MEDIUM
Matter - Denial of Service via CASE Sigma1 Message Replay
CVSS 6.5
CVE-2024-40634 HIGH
Argo CD < 2.9.20 - Unauthenticated Denial of Service via Large JSON Payload to Webhook Endpoint
CVSS 7.5
CVE-2024-32007 HIGH
Apache CXF <4.0.5, 3.6.4, 3.5.9 - DoS
CVSS 7.5
CVE-2024-21185 MEDIUM
MySQL Server 8.0.38, 8.4.1, 9.0.0 - Denial of Service in InnoDB
CVSS 4.9
CVE-2024-21177 MEDIUM
MySQL Server < 8.0.37 and 8.4.0 - Authenticated Denial of Service in Server Optimizer
CVSS 6.5
CVE-2024-21173 MEDIUM
MySQL < 8.0.37 and 8.4.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2024-21171 MEDIUM
MySQL Server 8.0.0-8.0.37 and 8.4.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2024-21163 MEDIUM
MySQL Server < 8.0.37 and <= 8.4.0 - Authenticated Denial of Service in Optimizer
CVSS 5.5
CVE-2024-21161 MEDIUM
Oracle VM VirtualBox < 7.0.20 - Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2024-21142 MEDIUM
MySQL Server: Security: Privileges < 8.0.37 and <= 8.4.0 - Authenticated Denial of Service
CVSS 4.9
CVE-2024-21130 MEDIUM
MySQL Server < 8.0.37 and <= 8.4.0 - Denial of Service in Optimizer
CVSS 4.9
CVE-2024-21127 MEDIUM
MySQL Server < 8.0.37 and 8.4.0 - Denial of Service in DDL Component
CVSS 4.9
CVE-2024-21126 MEDIUM
Oracle Database Server 19.3-19.23 and 21.3-21.14 - Unauthenticated Partial Denial of Service via DNS
CVSS 5.8
CVE-2024-20996 MEDIUM
MySQL < 8.0.37 and 8.4.0 - Denial of Service in InnoDB
CVSS 4.9
CVE-2024-5795 HIGH
GitHub Enterprise Server < 3.14 - Denial of Service via Large Payload to Git Server
CVSS 7.7
Details
Vulnerabilities 3,128
Exploit Likelihood High