CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,142 vulnerabilities with CWE-400
CVE-2022-47356 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Log Service
CVSS 5.5
CVE-2022-47355 MEDIUM
Google Android Log Service - Denial of Service
CVSS 5.5
CVE-2022-47354 MEDIUM
Google Android Log Service - Denial of Service
CVSS 5.5
CVE-2022-40513 HIGH
Qualcomm WLAN Firmware - Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2022-38674 MEDIUM
Android - Denial of Service in WLAN Driver via Missing Parameter Check
CVSS 5.5
CVE-2022-44572 HIGH
Rack < 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1 - Denial of Service via Multipart Boundary Parsing
CVSS 7.5
CVE-2022-44571 HIGH
Rack 2.0.0-2.0.9.1 - Denial of Service via Content-Disposition Header Parsing
CVSS 7.5
CVE-2022-44570 HIGH
Rack 1.5.0-2.0.9.1 - Denial of Service via Range Header Parsing
CVSS 7.5
CVE-2022-44566 HIGH
ActiveRecord < 6.1.7.1 - Denial of Service via PostgreSQL Integer Comparison
CVSS 7.5
CVE-2022-40480 MEDIUM
Microchip DT100112 Firmware - Denial of Service via Crafted ConReq Packet
CVSS 6.5
CVE-2022-42950 MEDIUM
Couchbase Server 7.0.0-7.0.4 and 7.1.0-7.1.1 - Authenticated Denial of Service via Backup Service REST Request
CVSS 4.9
CVE-2022-3094 HIGH
BIND 9.16.0-9.16.36 9.18.0-9.18.10 9.19.0-9.19.8 9.16.8-S1-9.16.36-S1 - Denial of Service via Dynamic DNS Update Flood
CVSS 7.5
CVE-2022-27508 HIGH
Citrix Application Delivery Controller and Gateway - Unauthenticated Denial of Service
CVSS 7.5
CVE-2022-27507 MEDIUM
Citrix Gateway 12.1-<12.1-64.17 and Application Delivery Controller 12.1-<12.1-55.278 - Authenticated Denial of Service
CVSS 6.5
CVE-2022-4816 MEDIUM
Lenovo Safecenter < 7.2.01.0315 - Denial of Service
CVSS 6.2
CVE-2022-41861 MEDIUM
FreeRADIUS < 3.0.25 - Denial of Service via Malformed Abinary Attribute
CVSS 6.5
CVE-2022-3613 MEDIUM
GitLab < 15.5.7, 15.6 < 15.6.4, 15.7 < 15.7.2 - Denial of Service via Prometheus Server Query
CVSS 5.8
CVE-2022-4344 MEDIUM
Wireshark 3.6.0-3.6.9 and 4.0.0-4.0.1 - Denial of Service via Kafka Protocol Dissector Memory Exhaustion
CVSS 6.3
CVE-2022-34335 MEDIUM
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, 6.2.1 - DoS via Resource Exhaustion
CVSS 6.5
CVE-2022-46740 MEDIUM
HUAWEI WS7100-20 Smart WiFi Router - Denial of Service via Wi-Fi Module
CVSS 6.5
CVE-2022-3064 HIGH
YAML Parser - Excessive Resource Consumption
CVSS 7.5
CVE-2022-4767 HIGH
memos < 0.9.1 - Denial of Service
CVSS 7.5
CVE-2022-24118 CRITICAL
General Electric Renewable Energy - Reboot
CVSS 9.1
CVE-2022-47934 MEDIUM
Brave < 1.43.88 - Denial of Service via ipfs:// or ipns:// URL Handling
CVSS 6.5
CVE-2022-47932 MEDIUM
Brave < 1.42.51 - Denial of Service via IPFS/IPNS URL Handling
CVSS 6.5
Details
Vulnerabilities 3,142
Exploit Likelihood High