CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,141 vulnerabilities with CWE-400
CVE-2023-34462 MEDIUM
Netty < 4.1.94 - Denial of Service via SniHandler Heap Allocation
CVSS 6.5
CVE-2023-2990 HIGH
Globalscape EFT Server < 8.1.0.16 - Denial of Service via Recursive Deflate Stream
CVSS 7.5
CVE-2023-26434 MEDIUM
open-xchange_appsuite_backend < 7.10.6 - Denial of Service via POP3 Capabilities Response
CVSS 4.3
CVE-2023-26433 MEDIUM
open-xchange_appsuite_backend < 7.10.6 - Denial of Service via IMAP Capabilities Response
CVSS 4.3
CVE-2023-26432 MEDIUM
open-xchange_appsuite_backend < 7.10.6 - Denial of Service via SMTP Capabilities Response
CVSS 4.3
CVE-2023-34166 HIGH
Huawei EMUI - Denial of Service via Abnormal API Callbacks
CVSS 7.5
CVE-2023-2831 MEDIUM
Mattermost 7.1.0-7.1.8 - Denial of Service via Markdown String Unescaping
CVSS 4.3
CVE-2023-2793 MEDIUM
Mattermost 7.8.0-7.8.2 - Denial of Service via Link Preview
CVSS 6.5
CVE-2023-2785 MEDIUM
Mattermost 7.1.0-7.1.8 - Denial of Service via PostgreSQL Error Log Message Truncation
CVSS 4.3
CVE-2023-2683 MEDIUM
EFR32 Bluetooth LE <5.1.1 - Memory Corruption
CVSS 5.3
CVE-2023-32229 MEDIUM
Bosch CPP13 and CPP14 Firmware - Denial of Service via Stream Security Option
CVSS 4.9
CVE-2023-29331 HIGH
Microsoft .NET and .NET Framework - Denial of Service
CVSS 7.5
CVE-2023-32013 MEDIUM
Windows 10/11, Server 2019/2022 Hyper-V Denial of Service
CVSS 5.3
CVE-2023-2778 HIGH
Rockwell Automation FactoryTalk Transaction Manager < 13.10 - Denial of Service via Modified Packet to Port 400
CVSS 7.5
CVE-2023-35053 HIGH
JetBrains YouTrack < 2023.1.10518 - Denial of Service via Helpdesk Forms
CVSS 7.5
CVE-2023-29767 MEDIUM
CrossX 1.15.3 - Denial of Service via Database Files
CVSS 5.5
CVE-2023-3163 LOW
RuoYi < 4.7.7 - Uncontrolled Resource Consumption via filterKeyword Function
CVSS 3.5
CVE-2023-34109 MEDIUM
zxcvbn-ts < 3.0.2 - Uncontrolled Resource Consumption via Second Argument of zxcvbn Function
CVSS 6.5
CVE-2023-33958 MEDIUM
notation-go < 1.0.0-rc.6 - Denial of Service via Excessive Signature Verification
CVSS 5.4
CVE-2023-33957 LOW
notation-go < 1.0.0 - Denial of Service via High Signature Count
CVSS 2.6
CVE-2023-34104 HIGH
fast-xml-parser < 4.2.4 - Denial of Service via Crafted Entity Name Regex
CVSS 7.5
CVE-2023-29544 MEDIUM
Firefox and Focus for Android < 112.0 - Memory Corruption via Garbage Collector
CVSS 6.5
CVE-2023-0616 MEDIUM
Thunderbird < 102.8 - Denial of Service via Crafted OpenPGP MIME Email
CVSS 6.5
CVE-2023-29735 MEDIUM
edjing Mix 7.09.01 - Denial of Service via Database Files
CVSS 5.5
CVE-2023-30570 HIGH
Libreswan 3.28-4.10 - Unauthenticated Denial of Service via IKEv1 Aggressive Mode Packets
CVSS 7.5
Details
Vulnerabilities 3,141
Exploit Likelihood High