CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,146 vulnerabilities with CWE-400
CVE-2022-39271 HIGH
Traefik < 2.8.8 - Denial of Service via HTTP/2 Connection Handling
CVSS 7.5
CVE-2022-38371 HIGH
APOGEE MBC/MEC/PXC Compact/Modular & Desigo - Info Disclosure
CVSS 7.5
CVE-2022-39280 MEDIUM
Pyup Dependency Parser < 0.5.1 - Denial of Service
CVSS 5.9
CVE-2022-2529 HIGH
cloudflare/goflow < 3.4.4 - Denial of Service via Malformed sFlow Packet
CVSS 7.5
CVE-2022-34326 HIGH
Realtek RTL8195AM Firmware < 2022-06-20 - Denial of Service via Wi-Fi Connection Failures in Soft AP Mode
CVSS 7.5
CVE-2022-3204 HIGH
Unbound < 1.16.3 - Denial of Service via Non-Responsive Delegation Attack
CVSS 7.5
CVE-2022-32790 HIGH
iPhone OS < 15.5 - Denial of Service
CVSS 7.5
CVE-2022-3257 LOW
Mattermost < 7.2.0 - Authenticated Denial of Service via Crafted GIF Upload
CVSS 3.1
CVE-2022-23951 MEDIUM
Keylime < 6.3.0 - Uncontrolled Resource Consumption via Zip Bomb in Agent Quote Response
CVSS 5.5
CVE-2022-28639 HIGH
HPE Integrated Lights-Out 5 Firmware < 2.72 - Denial of Service and Arbitrary Code Execution
CVSS 8.8
CVE-2022-37884 HIGH
Aruba ClearPass Policy Manager < 6.9.12 - Unauthenticated Denial of Service via Guest User Interface
CVSS 7.5
CVE-2022-28204 HIGH
MediaWiki 1.37.0-1.37.1 - Denial of Service via Special:WhatLinksHere Endpoint
CVSS 7.5
CVE-2022-40150 MEDIUM
jettison < 1.4.0 - Denial of Service via Uncontrolled Recursion
CVSS 6.5
CVE-2022-39209 HIGH
cmark-gfm < 0.29.0.gfm.6 - Denial of Service via Autolink Extension
CVSS 7.5
CVE-2022-36114 MEDIUM
Cargo < 0.65.0 - Uncontrolled Resource Consumption via Compressed Archive Extraction
CVSS 4.8
CVE-2022-2962 HIGH
QEMU 4.2.0-7.0.0 - Denial of Service via Tulip DMA Reentrancy
CVSS 7.8
CVE-2022-38013 HIGH
.NET Core and Visual Studio - Denial of Service
CVSS 7.5
CVE-2022-38100 HIGH
ContecHealth CMS8000 Firmware - Denial of Service via Malformed UDP Request
CVSS 7.5
CVE-2022-39158 MEDIUM
Siemens RUGGEDCOM ROS < 5.6.0 - Denial of Service via Partial HTTP Request Handling
CVSS 5.3
CVE-2022-31006 HIGH
Hyperledger Indy Node - Denial of Service via Connection Pool Exhaustion
CVSS 7.5
CVE-2022-3147 LOW
Mattermost < 7.1.0 - Authenticated Denial of Service via JPEG Image Upload
CVSS 3.1
CVE-2022-36083 MEDIUM
jose < 1.28.2, < 3.20.4, < 4.9.2 - Uncontrolled Resource Consumption via PBES2 Count Parameter
CVSS 5.3
CVE-2022-36049 HIGH
Helm 3.0.0-3.9.3 and Flux2 0.0.17-0.31.9 - Denial of Service via Memory Exhaustion
CVSS 7.7
CVE-2022-35913 MEDIUM
Samourai Wallet Stonewallx2 0.99.98e - DoS
CVSS 4.3
CVE-2022-36064 MEDIUM
Shescape - Inefficient Regular Expression Complexity
CVSS 5.9
Details
Vulnerabilities 3,146
Exploit Likelihood High