CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,141 vulnerabilities with CWE-400
CVE-2023-30406 MEDIUM
Jerryscript - Denial of Service via ecma_find_named_property
CVSS 5.5
CVE-2023-29479 MEDIUM
Ribose RNP < 0.16.3 - Denial of Service via Malformed Input
CVSS 5.3
CVE-2023-30798 HIGH
Starlette < 0.25.0 - Unauthenticated Denial of Service via MultipartParser
CVSS 7.5
CVE-2023-27652 MEDIUM
Ego Studio SuperClean 1.1.5-1.1.9 - XML External Entity Injection via Update Info Field
CVSS 5.5
CVE-2023-0384 MEDIUM
M-Files Server < 23.4.12528.1 - Denial of Service via Uncontrolled Memory Consumption in Scheduled Job
CVSS 6.5
CVE-2023-0383 HIGH
M-Files Server < 23.4.12528.1 - Denial of Service via Uncontrolled Memory Consumption
CVSS 7.5
CVE-2023-21090 MEDIUM
Android 13 - Uncontrolled Resource Consumption in ParsingPackageUtils.java
CVSS 5.0
CVE-2023-28440 LOW
Discourse <3.0.3, <3.1.0.beta4 - DoS
CVSS 2.7
CVE-2023-26048 MEDIUM
Eclipse Jetty < 9.4.51 - Denial of Service via Multipart Request with Large Content
CVSS 5.3
CVE-2023-21996 HIGH
Oracle WebLogic Server <14.1.1.0.0 - DoS
CVSS 7.5
CVE-2023-21964 HIGH
Oracle WebLogic Server <14.1.1.0.0 - DoS
CVSS 7.5
CVE-2023-21925 MEDIUM
Oracle Health Sciences InForm <6.3.1.3,7.0.0.1 - DoS
CVSS 5.3
CVE-2023-30769 CRITICAL
dogecoin < 1.14.6 - Denial of Service via Crafted Consensus Messages
CVSS 9.1
CVE-2023-29013 HIGH
Traefik < 2.9.10 - Denial of Service via HTTP Header Parsing
CVSS 7.5
CVE-2023-27643 HIGH
Poweramp - Denial of Service via Rescan and Select Folders Buttons
CVSS 7.5
CVE-2023-30635 HIGH
TiKV 6.1.2 - Denial of Service via Placement Driver Timestamp Request
CVSS 7.5
CVE-2023-20863 MEDIUM
Spring Framework < 5.2.24, 5.3.0-5.3.26, 6.0.0-6.0.7 - Denial of Service via SpEL Expression Injection
CVSS 6.5
CVE-2023-1994 MEDIUM
Wireshark 3.6.0-3.6.12 and 4.0.0-4.0.4 - Denial of Service via GQUIC Dissector Crash
CVSS 6.3
CVE-2023-24545 HIGH
Arista CloudEOS 4.26.0-4.26.9m - Denial of Service via Malformed Packet Buffer Leak
CVSS 7.5
CVE-2023-1992 MEDIUM
Wireshark 3.6.0-3.6.12 and 4.0.0-4.0.4 - Denial of Service via RPCoRDMA Dissector
CVSS 6.3
CVE-2023-28217 HIGH
Windows NAT - Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2023-24860 HIGH
Microsoft Malware Protection Engine < 1.1.20200.4 - Denial of Service
CVSS 7.5
CVE-2023-29185 MEDIUM
SAP NetWeaver AS ABAP Business Server Pages - Authenticated Denial of Service via Resource Consumption
CVSS 5.3
CVE-2023-28763 MEDIUM
SAP NetWeaver AS for ABAP and ABAP Platform - DoS
CVSS 6.5
CVE-2023-27191 HIGH
DUALSPACE Super Secuirty <2.3.7 - DoS
CVSS 7.5
Details
Vulnerabilities 3,141
Exploit Likelihood High