CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,141 vulnerabilities with CWE-400
CVE-2023-28320 MEDIUM
curl < 8.1.0 - Denial of Service via Synchronous Resolver Race Condition
CVSS 5.9
CVE-2023-1981 MEDIUM
avahi - Denial of Service via D-Bus Call
CVSS 5.5
CVE-2023-20883 HIGH
Spring Boot 2.5.0-2.5.14, 2.6.0-2.6.14, 2.7.0-2.7.11, 3.0.0-3.0.6 DoS via Reverse Proxy Cache
CVSS 7.5
CVE-2023-20882 MEDIUM
Cloudfoundry Cf-deployment < 29.0.0 - Denial of Service
CVSS 5.9
CVE-2023-33720 MEDIUM
mp4v2 <2.1.2 - Memory Corruption
CVSS 6.5
CVE-2023-32067 HIGH
c-ares < 1.19.1 - Denial of Service via Malformed UDP Packet
CVSS 7.5
CVE-2023-2798 HIGH
HtmlUnit < 2.70.0 - Denial of Service via Stack Overflow
CVSS 7.5
CVE-2023-33980 HIGH
Briar < 1.4.22 - Denial of Service via Long Messages in Bramble Synchronisation Protocol
CVSS 7.5
CVE-2023-26595 MEDIUM
Cybozu Garoon 4.10.0-5.9.2 - Authenticated Denial of Service via Message
CVSS 6.5
CVE-2023-33297 HIGH
Bitcoin Core < 24.1 - Denial of Service via Inventory Queue Drain Inefficiency
CVSS 7.5
CVE-2023-2295 HIGH
libreswan - Denial of Service via IKEv1 Aggressive Mode Packet Handling
CVSS 7.5
CVE-2023-26044 MEDIUM
ReactPHP HTTP 0.8.0-1.8.9 - Denial of Service via Large Request Body Processing
CVSS 5.3
CVE-2023-21110 HIGH
Android 11-13 - Local Privilege Escalation via SnoozeHelper Resource Exhaustion
CVSS 7.8
CVE-2023-20930 MEDIUM
Android 11-13 - Local Denial of Service via ShortcutPackage Resource Exhaustion
CVSS 5.5
CVE-2023-32787 HIGH
OPC UA Legacy Java Stack < 2023-04-28 - Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2023-31409 MEDIUM
SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Unauthenticated Denial of Service via Slowloris HTTP Requests
CVSS 5.3
CVE-2023-23447 HIGH
SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Unauthenticated Denial of Service via REST Interface
CVSS 7.5
CVE-2023-28356 HIGH
rocket.chat < 6.0.0 - Denial of Service via Malicious Message Processing
CVSS 7.5
CVE-2023-25568 HIGH
Boxo 0.4.0-0.5.0 - Memory Exhaustion via Bitswap Server Allocation
CVSS 8.2
CVE-2023-25179 MEDIUM
Intel Unite < 17 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.0
CVE-2023-29333 LOW
Microsoft 365 Apps - Denial of Service in Access
CVSS 3.3
CVE-2023-22874 MEDIUM
IBM MQ Appliance 9.2.0.0-9.3.1 and 9.3.0.0-9.3.0.4 - Denial of Service via Configuration File Processing
CVSS 5.5
CVE-2023-24594 MEDIUM
F5 F5 BIG-IP - Resource Consumption via SSL Traffic
CVSS 5.3
CVE-2023-28882 HIGH
OWASP ModSecurity 3.0.5-3.0.8 - Denial of Service via Transaction Class Segfault
CVSS 7.5
CVE-2023-30408 MEDIUM
jerryscript - Denial of Service via Segmentation Violation in build/bin/jerry
CVSS 5.5
Details
Vulnerabilities 3,141
Exploit Likelihood High