CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,141 vulnerabilities with CWE-400
CVE-2023-40709 MEDIUM
opto22 SNAP PAC S1 Firmware R10.3b - Denial of Service via ICMP Request Flood
CVSS 6.8
CVE-2023-37379 HIGH
Apache Airflow < 2.7.0 - Authenticated Denial of Service via Connection Test Feature
CVSS 8.1
CVE-2023-39748 HIGH
TP-Link TL-WR1041N V2 Firmware - Denial of Service via NetworkCfgRpm GET Request
CVSS 7.5
CVE-2023-4394 MEDIUM
Linux Kernel - Use-After-Free in btrfs_get_dev_args_from_path
CVSS 6.7
CVE-2023-38737 MEDIUM
IBM WebSphere Application Server Liberty <23.0.0.7 - DoS
CVSS 5.9
CVE-2023-21280 MEDIUM
Android - Denial of Service via MediaSessionRecord Resource Exhaustion
CVSS 5.5
CVE-2023-38741 HIGH
IBM TXSeries for Multiplatforms <9.1 - DoS
CVSS 7.5
CVE-2023-28938 LOW
Intel(R) SSD Tools <mdadm-4.2-rc2 - Privilege Escalation
CVSS 3.4
CVE-2023-38210 MEDIUM
Adobe XMP Toolkit < 2022.06 - Unauthenticated Denial of Service via Malicious File Processing
CVSS 5.5
CVE-2023-38180 HIGH KEV
.NET 6.0.0-6.0.20 and ASP.NET Core 2.1-2.1.39 - Denial of Service
CVSS 7.5
CVE-2023-38178 HIGH
.NET 7.0.0-7.0.9 and Visual Studio 2022 17.2.0-17.2.17 - Denial of Service
CVSS 7.5
CVE-2023-29409 MEDIUM
GO < 1.19.12 - Denial of Service
CVSS 5.3
CVE-2023-3825 HIGH
KEPServerEX 6.0-6.14.263 - Denial of Service via Recursive OPC UA Object Decoding
CVSS 7.5
CVE-2023-34872 MEDIUM
poppler < 23.06.0 - Denial of Service via Crafted PDF in OutlineItem::open
CVSS 5.5
CVE-2023-38498 MEDIUM
Discourse <3.0.6-3.1.0.beta7 - Info Disclosure
CVSS 4.3
CVE-2023-37900 LOW
Crossplane < 1.11.5, 1.12.3, 1.13.0 - Denial of Service via Large Package Image Parsing
CVSS 3.4
CVE-2023-3637 MEDIUM
Red Hat OpenStack Platform - Authenticated Denial of Service via Security Group Query
CVSS 4.3
CVE-2023-38200 HIGH
Keylime < 7.4.0 - Denial of Service via SSL Connection Exhaustion
CVSS 7.5
CVE-2023-3782 MEDIUM
okhttp-brotli - Denial of Service via Brotli Zip-Bomb
CVSS 5.9
CVE-2023-37143 MEDIUM
ChakraCore - Denial of Service via BackwardPass::IsEmptyLoopAfterMemOp()
CVSS 5.5
CVE-2023-37142 MEDIUM
ChakraCore - Denial of Service via Js::EntryPointInfo::HasInlinees()
CVSS 5.5
CVE-2023-37141 MEDIUM
ChakraCore - Denial of Service via Js::ProfilingHelpers::ProfiledNewScArray()
CVSS 5.5
CVE-2023-37140 MEDIUM
ChakraCore - Denial of Service via Js::DiagScopeVariablesWalker::GetChildrenCount()
CVSS 5.5
CVE-2023-37788 HIGH
goproxy - Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2023-37481 LOW
Fides 2.11.0-2.15.1 - Authenticated Denial of Service via SVG Bomb in Zip Upload
CVSS 2.7
Details
Vulnerabilities 3,141
Exploit Likelihood High