CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,139 vulnerabilities with CWE-400
CVE-2024-20961 MEDIUM
MySQL Server < 8.0.35 and 8.2.0 - Authenticated Denial of Service in Optimizer
CVSS 6.5
CVE-2024-20959 MEDIUM
Oracle ZFS Storage Appliance Kit 8.8 - Denial of Service in Core Component
CVSS 4.4
CVE-2024-0581 MEDIUM
Sandsprite scdbg 1.0 - Uncontrolled Resource Consumption via '/foff' Parameter
CVSS 4.0
CVE-2024-22362 HIGH
Drupal - Denial of Service via Improper Handling of Structural Elements
CVSS 7.5
CVE-2024-21655 MEDIUM
Discourse < 3.1.4 - Unauthenticated Resource Exhaustion via Client-Editable Fields
CVSS 4.3
CVE-2024-0348 MEDIUM
Engineers Online Portal 1.0 - Resource Consumption in File Upload Handler
CVSS 4.3
CVE-2024-20672 HIGH
.NET 6.0.0-6.0.25 - Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2024-20661 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-23H2 - Denial of Service in Microsoft Message Queuing
CVSS 7.5
CVE-2024-22164 MEDIUM
Splunk Enterprise Security < 7.1.2 - Denial of Service via Investigation Attachment Endpoint
CVSS 4.3
CVE-2024-21651 HIGH
XWiki 14.10-14.10.17 - Denial of Service via Malformed TAR File Attachment
CVSS 7.5
CVE-2024-0241 HIGH
Diaconou Encodedid < 1.0.0 - Denial of Service
CVSS 7.5
CVE-2023-54365 HIGH
Traefik - Denial of Service via HTTP/2 Request Handling
CVSS 7.5
CVE-2023-53873 HIGH
SyncBreeze 15.2.24 - Denial of Service via Login Endpoint Password Parameter Overflow
CVE-2023-7326 HIGH
Epson Stylus SX510W < 2023-05-13 - Denial of Service via Malformed Query Parameters
CVE-2023-42983 MEDIUM
macOS < 14.0 - Denial of Service and Memory Disclosure via File Processing
CVSS 6.4
CVE-2023-51316 HIGH
PHPJabbers Bus Reservation System <1.1 - DoS
CVSS 7.5
CVE-2023-51314 HIGH
PHPJabbers Restaurant Booking System <3.0 - DoS
CVSS 7.5
CVE-2023-51301 HIGH
PHPJabbers Hotel Booking System <4.0 - DoS
CVSS 7.5
CVE-2023-51293 HIGH
PHPJabbers Event Booking Calendar v4.0 - DoS
CVSS 7.5
CVE-2023-34397 HIGH
Mercedes-Benz Head-Unit NTG6 < 2021 - Denial of Service via USB Profile Import
CVSS 7.5
CVE-2023-37022 HIGH
Open5GS <= 2.6.4 - Denial of Service via MME_UE_S1AP_ID Assertion Failure
CVSS 7.5
CVE-2023-37014 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 7.5
CVE-2023-39180 MEDIUM
Linux Kernel - Denial of Service via SMB2_READ Memory Leak in ksmbd
CVSS 4.0
CVE-2023-20125 HIGH
Cisco BroadWorks Network Server - DoS
CVSS 8.6
CVE-2023-28451 HIGH
Technitium DNS Server 11.0.2 - Denial of Service via BadDNS Response Forgery
CVSS 7.5
Details
Vulnerabilities 3,139
Exploit Likelihood High