CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,142 vulnerabilities with CWE-400
CVE-2022-43766 HIGH
Apache IoTDB <0.12.7, >0.13.2 - DoS
CVSS 7.5
CVE-2022-3639 MEDIUM
GitLab 10.8.0-15.1.5, 15.2.0-15.2.3, 15.3.0-15.3.1 - Denial of Service via Branch Creation
CVSS 4.3
CVE-2022-41833 HIGH
F5 BIG-IP 13.1.0-13.1.4 - Denial of Service via HTTP::collect iRule
CVSS 7.5
CVE-2022-41806 HIGH
BIG-IP <16.1.3.2 & 15.1.5.1 - Memory Corruption
CVSS 7.5
CVE-2022-41770 MEDIUM
BIG-IP <17.0.0.1,16.1.3.1,15.1.7,14.1.5.1,13.1.x - Memory Corruption
CVSS 6.5
CVE-2022-3517 HIGH
minimatch < 3.0.5 - Denial of Service via braceExpand Function
CVSS 7.5
CVE-2022-3283 HIGH
GitLab CE/EE <15.2.5, <15.3.4, <15.4.1 - DoS
CVSS 7.5
CVE-2022-2931 HIGH
GitLab < 15.1.6, 15.2-15.2.4, 15.3-15.3.2 - Denial of Service via Malformed Issue Description
CVSS 7.5
CVE-2022-2455 MEDIUM
GitLab 10.0.0-15.1.5, 15.2.0-15.2.3, 15.3.0-15.3.1 - Authenticated Resource Exhaustion via Malicious Project Import
CVSS 6.5
CVE-2022-39128 MEDIUM
Android - Local Denial of Service via Sensor Driver Missing Bounds Check
CVSS 5.5
CVE-2022-39127 MEDIUM
Android - Local Denial of Service via Sensor Driver Missing Bounds Check
CVSS 5.5
CVE-2022-39126 MEDIUM
Android - Local Denial of Service via Sensor Driver Missing Bounds Check
CVSS 5.5
CVE-2022-39125 MEDIUM
Android - Local Denial of Service via Sensor Driver Missing Bounds Check
CVSS 5.5
CVE-2022-39124 MEDIUM
Android - Local Denial of Service via Sensor Driver Missing Bounds Check
CVSS 5.5
CVE-2022-39123 MEDIUM
Android - Local Denial of Service via Sensor Driver Missing Bounds Check
CVSS 5.5
CVE-2022-38687 MEDIUM
Android - Denial of Service via Missing Authorization in Messaging Service
CVSS 5.5
CVE-2022-38679 MEDIUM
Android - Missing Authorization Leading to Local Denial of Service in Music Service
CVSS 5.5
CVE-2022-38677 MEDIUM
Android - Unauthenticated Denial of Service in Cell Service
CVSS 5.5
CVE-2022-39278 HIGH
Istio < 1.13.9 - Unauthenticated Denial of Service via Oversized Webhook Message
CVSS 7.5
CVE-2022-41404 HIGH
ini4j <= 0.5.4 - Denial of Service via BasicProfile fetch() Method
CVSS 7.5
CVE-2022-20425 MEDIUM
Android - Local Denial of Service via ZenModeHelper Resource Exhaustion
CVSS 5.5
CVE-2022-39271 HIGH
Traefik < 2.8.8 - Denial of Service via HTTP/2 Connection Handling
CVSS 7.5
CVE-2022-38371 HIGH
APOGEE MBC/MEC/PXC Compact/Modular & Desigo - Info Disclosure
CVSS 7.5
CVE-2022-39280 MEDIUM
Pyup Dependency Parser < 0.5.1 - Denial of Service
CVSS 5.9
CVE-2022-2529 HIGH
cloudflare/goflow < 3.4.4 - Denial of Service via Malformed sFlow Packet
CVSS 7.5
Details
Vulnerabilities 3,142
Exploit Likelihood High