CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-34308 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in JSON Component
CVSS 6.5
CVE-2026-34304 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-34303 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2026-34293 MEDIUM
MySQL Server 8.0.0-8.0.45 - Authenticated Denial of Service in DML Component
CVSS 4.9
CVE-2026-34290 HIGH
Oracle Corporation Oracle Identity Manager Connector < 12.2.1.4.0 - Denial of Service
CVSS 7.5
CVE-2026-34282 HIGH
Oracle Java SE & GraalVM DoS via Networking Component
CVSS 7.5
CVE-2026-34281 MEDIUM
Oracle Solaris 11.4 - Denial of Service in Kernel
CVSS 6.5
CVE-2026-34278 MEDIUM
MySQL Server 8.0.0-8.0.45 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-34277 MEDIUM
PeopleSoft Enterprise PeopleTools 8.61-8.62 - Authenticated Improper Access Control in Fluid Core
CVSS 6.6
CVE-2026-34276 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Group Replication Plugin
CVSS 6.5
CVE-2026-34272 MEDIUM
MySQL Server 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2026-34271 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Group Replication Plugin
CVSS 6.5
CVE-2026-34270 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Group Replication Plugin
CVSS 6.5
CVE-2026-34267 MEDIUM
MySQL Server 8.0.0-8.0.45 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-22021 MEDIUM
Oracle Java SE & GraalVM for JDK - Unauthenticated Partial DoS via JSSE
CVSS 5.3
CVE-2026-22017 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2026-22009 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2026-22005 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-22004 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-22003 MEDIUM
Oracle Java SE 8u481, 8u481-b50 and GraalVM Enterprise Edition 21.3.17 - Uncontrolled Resource Consumption in Hotspot
CVSS 6.0
CVE-2026-22002 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 4.9
CVE-2026-21998 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in Optimizer
CVSS 4.9
CVE-2026-6781 HIGH
Denial-of-service in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-6780 HIGH
Denial-of-service in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-6777 MEDIUM
Mozilla Firefox and Thunderbird 150 - DNS Component Input Validation Issue
CVSS 5.3
Details
Vulnerabilities 3,094
Exploit Likelihood High