CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,141 vulnerabilities with CWE-400
CVE-2023-24534 HIGH
Golang Go < 1.19.8 - Denial of Service via HTTP and MIME Header Parsing
CVSS 7.5
CVE-2023-1787 MEDIUM
GitLab <15.9.4-15.10.1 - Info Disclosure
CVSS 4.3
CVE-2023-1071 LOW
GitLab 15.5-15.8.4, 15.9-15.9.3, 15.10 - Unauthenticated Issue Removal from Epic via Improper Permissions Check
CVSS 3.1
CVE-2023-1733 MEDIUM
GitLab 11.10-15.8.5, 15.9-15.9.4, 15.10-15.10.1 - Denial of Service in Prometheus Server
CVSS 5.8
CVE-2023-28342 HIGH
ManageEngine ADSelfService Plus < 6218 - Unauthenticated Denial of Service via Mobile App Authentication API
CVSS 7.5
CVE-2023-20051 MEDIUM
Cisco Packet Data Network Gateway - DoS
CVSS 5.8
CVE-2023-0382 MEDIUM
M-Files Server < 23.4.12528.1 - Denial of Service via Uncontrolled Memory Consumption
CVSS 6.5
CVE-2023-27734 MEDIUM
edb-debugger 1.3.0 - Denial of Service via collect_symbols Function
CVSS 5.5
CVE-2023-26437 LOW
PowerDNS Recursor < 4.6.6 - Denial of Service via Authoritative Server Unavailability
CVSS 3.4
CVE-2023-28837 MEDIUM
Wagtail < 4.1.4 and 4.2-4.2.2 - Authenticated Denial of Service via Large File Upload
CVSS 4.9
CVE-2023-1580 HIGH
Dovolations Gateway <2023.1.1 - DoS
CVSS 7.5
CVE-2023-26485 MEDIUM
cmark-gfm < 0.29.0.gfm.10 - Denial of Service via Underscore Character Parsing
CVSS 5.3
CVE-2023-24824 MEDIUM
cmark-gfm < 0.29.0.gfm.10 - Denial of Service via Quadratic Complexity in Blockquote or List Parsing
CVSS 5.3
CVE-2023-29139 MEDIUM
MediaWiki < 1.39.3 - Denial of Service via CheckUserLog API Request Flood
CVSS 6.5
CVE-2023-28846 MEDIUM
unpoly-rails < 2.7.2.2 - Denial of Service via Excessively Long URL Response Header
CVSS 5.9
CVE-2023-28644 MEDIUM
Nextcloud Server 25.0.0-25.0.2 - Denial of Service via Inefficient Fetch Operation
CVSS 5.7
CVE-2023-28507 CRITICAL
Rocket Software UniData <8.2.4-11.3.5-12.2.1 - Memory Corruption
CVSS 9.8
CVE-2023-28626 MEDIUM
comrak < 0.17.0 - Denial of Service via Quadratic Parsing
CVSS 5.3
CVE-2023-1654 HIGH
gpac < 2.2.0 - Denial of Service
CVSS 7.8
CVE-2023-21061 HIGH
Android - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2023-21033 MEDIUM
Android 13 - Denial of Service via WifiManager addNetwork Resource Exhaustion
CVSS 5.5
CVE-2023-20911 HIGH
Android - Local Privilege Escalation via Permission Settings Exhaustion
CVSS 7.8
CVE-2023-20910 MEDIUM
Android - Denial of Service via WifiNetworkSuggestionsManager Resource Exhaustion
CVSS 5.5
CVE-2023-20861 MEDIUM
Spring Framework 5.2.0-5.2.22, 5.3.0-5.3.25, 6.0.0-6.0.6 - Denial of Service via SpEL Expression
CVSS 6.5
CVE-2023-0056 MEDIUM
HAProxy - Denial of Service via Uncontrolled Resource Consumption
CVSS 6.5
Details
Vulnerabilities 3,141
Exploit Likelihood High