CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,134 vulnerabilities with CWE-400
CVE-2024-3789 MEDIUM
White Bear Solutions WBSAirback <21.02.04 - Command Injection
CVSS 6.5
CVE-2024-34079 LOW
octo-sts app < 0.1.0 - Denial of Service via Resource Consumption
CVSS 3.7
CVE-2024-33774 MEDIUM
D-Link DIR-619L Rev.B 2.06B1 - Authenticated Denial of Service via formWlanSetup_Wizard Webpage Parameter
CVSS 6.5
CVE-2024-32476 MEDIUM
Argo CD 2.1.0-2.8.16, 2.10.0-2.10.7 - Denial of Service via jq in ignoreDifferences
CVSS 6.5
CVE-2024-33382 MEDIUM
Open5GS 2.7.0 - Denial of Service via Unsuccessful UE/gnb Registration
CVSS 5.3
CVE-2024-4438 HIGH
Red Hat OpenStack Platform 16.1-18.0 - Uncontrolled Resource Consumption via HTTP/2 Rapid Reset
CVSS 7.5
CVE-2024-4437 HIGH
Red Hat OpenStack Platform 16.1-18.0 - Uncontrolled Resource Consumption in etcd Package
CVSS 7.5
CVE-2024-4436 HIGH
Red Hat OpenStack Platform 16.1-18.0 - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2024-1930 MEDIUM
dnf5 < 5.1.17 - Denial of Service via Unlimited D-Bus Session Creation
CVSS 6.5
CVE-2024-23712 MEDIUM
Android - Local Denial of Service via AppOpsService Resource Exhaustion
CVSS 5.5
CVE-2024-0026 MEDIUM
Android - Denial of Service via Resource Exhaustion in SnoozeHelper
CVSS 5.5
CVE-2024-34084 HIGH
Minder < 0.0.48 - Unauthenticated Denial of Service via HandleGithubWebhook
CVSS 7.5
CVE-2024-32663 HIGH
Suricata 6.0.0-6.0.18 - Denial of Service via HTTP/2 Memory Exhaustion
CVSS 7.5
CVE-2024-4599 HIGH
LAN Messenger 3.4.0 - Denial of Service via UDP Long String
CVSS 7.5
CVE-2024-32972 HIGH
go-ethereum < 1.13.15 - Uncontrolled Resource Consumption via P2P Message Handling
CVSS 7.5
CVE-2024-4549 HIGH
Delta Electronics DIAEnergie < 1.10.01.004 - Denial of Service via ICS Restart Message
CVSS 7.5
CVE-2024-34506 HIGH
MediaWiki <1.39.7, 1.40.x <1.40.3, 1.41.x <1.41.1 - DoS
CVSS 7.5
CVE-2024-34483 HIGH
Faucet SDN Ryu 4.34 - Denial of Service via OFPBucket.len=0
CVSS 7.5
CVE-2024-25355 HIGH
s3-url-parser 1.0.3 - Denial of Service via Regexes Component
CVSS 7.5
CVE-2024-32984 HIGH
yamux 0.13.0-0.13.1 - Uncontrolled Resource Consumption via Unbounded Pending Frames Queue
CVSS 7.5
CVE-2024-26976 HIGH
Linux Kernel - Use-After-Free in KVM Async Page Fault Workqueue
CVSS 7.0
CVE-2024-34045 HIGH
O-RAN E2T I-Release - Denial of Service in Prometheus Metric Increment Function
CVSS 7.5
CVE-2024-32269 HIGH
Yonganda YAD-LOJ V3.0.561 - Denial of Service via Crafted Packet
CVSS 7.5
CVE-2024-2757 HIGH
PHP 8.3.0-8.3.4 - Denial of Service via mb_encode_mimeheader Function
CVSS 7.5
CVE-2024-33259 MEDIUM
jerryscript - Denial of Service via Scanner Seek Function
CVSS 5.5
Details
Vulnerabilities 3,134
Exploit Likelihood High