CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,146 vulnerabilities with CWE-400
CVE-2022-31173
HIGH
Juniper < 0.15.10 - Uncontrolled Recursion
CVSS 7.5
CVE-2022-24294
HIGH
Apache MXNet < 1.9.1 - Denial of Service via Crafted Operator Name
CVSS 7.5
CVE-2022-27937
HIGH
Pexip Infinity < 27.3 - Denial of Service via H.264 Resource Consumption
CVSS 7.5
CVE-2022-2406
MEDIUM
Mattermost <= 6.7.0 - Authenticated Denial of Service via Slack Import REST API
CVSS 4.3
CVE-2022-31080
MEDIUM
KubeEdge <1.11.1, <1.10.2, <1.9.4 - DoS
CVSS 4.4
CVE-2022-31079
MEDIUM
KubeEdge <1.11.1, 1.10.2, 1.9.4 - DoS
CVSS 4.4
CVE-2022-31078
MEDIUM
KubeEdge < 1.9.4, 1.10.0-1.10.1 - Authenticated Denial of Service via CloudCore Router REST Handler
CVSS 4.4
CVE-2022-31075
MEDIUM
KubeEdge < 1.9.4, 1.10.0-1.10.1, >=1.11.0 <1.11.1 - Authenticated Denial of Service via Large HTTP Request Body
CVSS 4.9
CVE-2022-31074
MEDIUM
KubeEdge < 1.9.4, 1.10.0-1.10.1, 1.11.0 - Denial of Service via Large HTTP Request Body
CVSS 4.5
CVE-2022-31073
MEDIUM
KubeEdge < 1.9.4, 1.10.0-1.10.1 - Denial of Service via Large HTTP Request Body
CVSS 6.5
CVE-2022-30792
HIGH
CODESYS V3 Control Runtime - Unauthenticated Denial of Service via CmpChannelServer Connection Exhaustion
CVSS 7.5
CVE-2022-30791
HIGH
CODESYS V3 - Unauthenticated Denial of Service via TCP Connection Exhaustion
CVSS 7.5
CVE-2022-20808
HIGH
Cisco Smart Software Manager On-Prem 8-202112 - Authenticated Denial of Service via Device Registration Requests
CVSS 7.7
CVE-2022-31129
HIGH
moment 2.18.0-2.29.3 - Denial of Service via RFC2822 Date Parsing
CVSS 7.5
CVE-2022-30591
HIGH
quic-go < 0.27.0 - Denial of Service via MTU Discovery Probe Timer Overflow
CVSS 7.5
CVE-2022-31110
MEDIUM
RSSHub < 2022-06-21 - Denial of Service via Inefficient Regular Expression in Filter Parameters
CVSS 5.3
CVE-2022-26477
HIGH
Apache SystemDS < 2.2.1 - Uncontrolled Resource Consumption via For Loop Termination Condition
CVSS 7.5
CVE-2022-31016
MEDIUM
Argo CD 0.7.0-2.1.15 - Authenticated Denial of Service via Large File Processing
CVSS 6.5
CVE-2022-31803
MEDIUM
CODESYS Gateway Server 2.0-2.3.9.38 - Unauthenticated Denial of Service via TCP Connection Exhaustion
CVSS 5.3
CVE-2022-29866
HIGH
OPC UA .NET Standard Stack < 1.4.368.58 - Denial of Service via Memory Resource Exhaustion
CVSS 7.5
CVE-2022-29864
HIGH
OPC UA .NET Standard Stack < 1.4.368.58 - Denial of Service via Message Flood
CVSS 7.5
CVE-2022-27889
MEDIUM
Palantir Foundry Multipass < 3.647.0 - Denial of Service via Authentication/Authorization Operations
CVSS 5.3
CVE-2022-31054
HIGH
Argo Events < 1.7.1 - Denial of Service via HandleRoute Endpoint
CVSS 7.5
CVE-2022-29225
HIGH
envoyproxy/envoy < 1.22.1 - Denial of Service via Zip Bomb Decompression
CVSS 7.5
CVE-2022-31030
MEDIUM
containerd < 1.5.13 - Uncontrolled Resource Consumption via ExecSync API
CVSS 5.5
Details
Vulnerabilities
3,146
Exploit Likelihood
High