CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,147 vulnerabilities with CWE-400
CVE-2021-28510 MEDIUM
Arista EOS < 4.23.10 - Denial of Service via Invalid PTP TLV
CVSS 5.3
CVE-2021-32821 MEDIUM
MooTools < 1.6.0 - Regular Expression Denial of Service via CSS Selector Parser
CVSS 6.2
CVE-2021-3821 CRITICAL
HP FutureSmart 5 < 5.3 - Denial of Service via HP Workpath Solutions
CVSS 9.8
CVE-2021-3735 MEDIUM
QEMU - Denial of Service via AHCI Controller Deadlock
CVSS 4.4
CVE-2021-3669 MEDIUM
Linux Kernel - Denial of Service via Shared Memory Segment Count Exhaustion
CVSS 5.5
CVE-2021-4022 MEDIUM
rizin < 0.3.1 - Denial of Service via HPPA ELF64 Binary Parsing
CVSS 5.5
CVE-2021-42521 HIGH
VTK < 9.2.5 - Denial of Service via NULL Pointer Dereference in vtkXMLTreeReader
CVSS 7.5
CVE-2021-4040 MEDIUM
AMQ Broker < 7.10.0 - Uncontrolled Resource Consumption via Maliciously Crafted Messages
CVSS 5.3
CVE-2021-3764 MEDIUM
Linux Kernel < 5.14.20 - Memory Leak in ccp_run_aes_gcm_cmd
CVSS 5.5
CVE-2021-3759 MEDIUM
Linux Kernel - Denial of Service via Semaphore Resource Starvation in IPC
CVSS 5.5
CVE-2021-3690 HIGH
Redhat Fuse < 2.0.40 - Memory Leak
CVSS 7.5
CVE-2021-3670 MEDIUM
Samba 4.1.0-4.15.9 - Uncontrolled Resource Consumption via MaxQueryDuration LDAP Bypass
CVSS 6.5
CVE-2021-20298 HIGH
OpenEXR < 2.5.7 - Denial of Service via B44Compressor Memory Exhaustion
CVSS 7.5
CVE-2021-22642 HIGH
Ovarro TBox < 1.46 - Denial of Service via Crafted Modbus Frames
CVSS 7.5
CVE-2021-3629 MEDIUM
Redhat Integration < 2.0.40 - Denial of Service
CVSS 5.9
CVE-2021-33135 MEDIUM
Intel Software Guard Extensions < 2.14 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2021-43933 MEDIUM
FANUC ROBOGUIDE <= 9.40083.00.05 - Denial of Service
CVSS 6.1
CVE-2021-41119 MEDIUM
wire-server < 2022-03-01 - Denial of Service via Hash Collision
CVSS 5.3
CVE-2021-32503 MEDIUM
SICK FTMG Firmware < 2.8 - Unauthenticated Sensitive Information Exposure via Web URL Access
CVSS 4.9
CVE-2021-22100 MEDIUM
Cloud Foundry CAPI < 1.122.0 and cf-deployment < 17.1.0 - Denial of Service via Malicious Service Broker
CVSS 5.3
CVE-2021-3733 MEDIUM
Python < 3.6.14 - Regular Expression Denial of Service in urllib AbstractBasicAuthHandler
CVSS 6.5
CVE-2021-3737 HIGH
Python >=3.6.0 <3.6.14 - Denial of Service via HTTP Response Handling
CVSS 7.5
CVE-2021-4021 HIGH
radare2 < 5.5.0 - Uncontrolled Resource Consumption via ELF64 MIPS Section Mapping
CVSS 7.5
CVE-2021-4115 MEDIUM
polkit - Unauthenticated Denial of Service via File Descriptor Exhaustion
CVSS 5.5
CVE-2021-0092 MEDIUM
Intel Atom and Core i3 Processors - Denial of Service via Local Access
CVSS 4.4
Details
Vulnerabilities 3,147
Exploit Likelihood High