CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,141 vulnerabilities with CWE-400
CVE-2023-50121 MEDIUM
Autel EVO NANO Drone Firmware 1.6.5 - Denial of Service
CVSS 5.7
CVE-2023-34324 MEDIUM
Linux Kernel < 5.10 - Deadlock via Event Channel Closure
CVSS 4.9
CVE-2023-42358 HIGH
O-RAN Software Community ric-plt-e2mgr - Denial of Service via E2Manager API
CVSS 7.7
CVE-2023-49557 MEDIUM
YASM 1.3.0.86.g9def - Denial of Service via yasm_section_bcs_first Function
CVSS 5.5
CVE-2023-49555 MEDIUM
YASM 1.3.0.86.g9def - Denial of Service via expand_smacro Function
CVSS 5.5
CVE-2023-49550 HIGH
Cesanta mjs 2.20.0 - Denial of Service via mjs+0x4ec508 Component
CVSS 7.5
CVE-2023-50020 HIGH
open5gs v2.6.6 - Denial of Service via SIGPIPE
CVSS 7.5
CVE-2023-50019 MEDIUM
open5gs v2.6.6 - Denial of Service via Nudm_UECM_Registration Response Error Handling
CVSS 5.9
CVE-2023-26157 MEDIUM
libredwg < 0.12.5.6384 - Denial of Service via Out-of-Bounds Read in decode_r2007.c
CVSS 5.5
CVE-2023-50730 HIGH
Grackle < 0.18.0 - Denial of Service via Cyclic Fragment or Deeply Nested Query Parsing
CVSS 7.5
CVE-2023-46131 MEDIUM
Grails <3.3.17, 4.1.3, 5.3.4, 6.1.0 - DoS
CVSS 6.5
CVE-2023-50249 HIGH
Sentry Astro 7.78.0-7.86.0 - Regular Expression Denial of Service
CVSS 7.5
CVE-2023-50707 CRITICAL
efacec BCU 500 Firmware - Denial of Service via Active Session Requests
CVSS 9.6
CVE-2023-46104 MEDIUM
Apache Superset <= 2.1.2, 3.0.0-3.0.1 - Authenticated Uncontrolled Resource Consumption via Malicious ZIP Import
CVSS 6.5
CVE-2023-41151 HIGH
Softing OPC UA C++ SDK <6.30 - Info Disclosure
CVSS 7.5
CVE-2023-6193 MEDIUM
quiche 0.15.0-0.19.0 - Unauthenticated Uncontrolled Resource Consumption via PATH_CHALLENGE Frame Queue
CVSS 5.3
CVE-2023-49713 HIGH
JTEKT GC-A2 Series Firmware - Unauthenticated Denial of Service via NetBIOS Packet
CVSS 7.5
CVE-2023-49143 HIGH
JTEKT GC-A2 Series Firmware - Unauthenticated Denial of Service via rfe Service
CVSS 7.5
CVE-2023-49140 HIGH
JTEKT GC-A2 Series Firmware - Unauthenticated Denial of Service via Crafted Packets
CVSS 7.5
CVE-2023-41963 HIGH
JTEKT GC-A2 Series Firmware - Unauthenticated Denial of Service via FTP Service
CVSS 7.5
CVE-2023-49809 MEDIUM
Mattermost Server < 8.1.5 - Denial of Service via Null Request Body in /add Endpoint
CVSS 4.3
CVE-2023-45847 MEDIUM
Mattermost < 7.8.14 - Denial of Service via Playbooks Checklist Title Length
CVSS 4.3
CVE-2023-5870 LOW
PostgreSQL >=11.0 <11.22 - Denial of Service via pg_cancel_backend Role
CVSS 2.2
CVE-2023-49800 HIGH
nuxt-api-party < 0.22.1 - Denial of Service via Recursive Retry Logic
CVSS 7.5
CVE-2023-4486 HIGH
Johnson Controls Metasys NAE55/SNE/SNC & Facility Explorer F4-SNC <12.0.4 DoS via Invalid Credentials
CVSS 7.5
Details
Vulnerabilities 3,141
Exploit Likelihood High