CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,148 vulnerabilities with CWE-400
CVE-2021-39171 MEDIUM
passport-saml < 3.1.0 - Denial of Service via Excessive SAML Transform Processing
CVSS 5.3
CVE-2021-33580 HIGH
Apache Roller < 6.0.2 - Denial of Service via Regex Catastrophic Backtracking
CVSS 7.5
CVE-2021-0008 MEDIUM
Intel Ethernet Controller E810 Firmware < 1.5.3.0 - Denial of Service via Uncontrolled Resource Consumption
CVSS 4.4
CVE-2021-25659 HIGH
Automation License Manager 5.x and 6.x < 6.0.9 - Denial of Service via Crafted Packets to Port 4410
CVSS 7.5
CVE-2021-3679 MEDIUM
Linux Kernel < 5.14 - Authenticated Denial of Service via Trace Ring Buffer Resource Starvation
CVSS 5.5
CVE-2021-22124 HIGH
FortiAuthenticator <6.0.6 & FortiSandbox 3.0.0-3.2.2 - DoS via Long Request Parameters
CVSS 7.5
CVE-2021-21565 MEDIUM
Dell PowerScale OneFS < 9.1.0.3 - Denial of Service via SmartConnect Error Condition
CVSS 5.3
CVE-2021-25701 MEDIUM
PCoIP Software Client < 21.07.0 - Denial of Service via fUSBHub Driver IOCTL Handling
CVSS 5.5
CVE-2021-32763 MEDIUM
OpenProject <11.3.3 - Info Disclosure
CVSS 4.3
CVE-2021-32014 MEDIUM
SheetJS and SheetJS Pro < 0.16.9 - Denial of Service via Crafted .xlsx Document
CVSS 5.5
CVE-2021-32013 MEDIUM
SheetJS and SheetJS Pro < 0.16.9 - Denial of Service via Crafted XLSX Document
CVSS 5.5
CVE-2021-32012 MEDIUM
SheetJS and SheetJS Pro < 0.16.9 - Denial of Service via Crafted XLSX Document
CVSS 5.5
CVE-2021-0292 MEDIUM
Juniper Networks Junos OS Evolved - DoS
CVSS 6.5
CVE-2021-0285 HIGH
Junos OS QFX5000/EX4600 < Multiple Versions - DoS via ICCP Interruptions
CVSS 7.5
CVE-2021-36716 HIGH
Segment is-email < 1.0.1 - Uncontrolled Resource Consumption via isEmail Function
CVSS 7.5
CVE-2021-32740 HIGH
Addressable 2.3.0-2.7.0 - Denial of Service via URI Template Matching
CVSS 7.5
CVE-2021-22119 HIGH
Spring Security 5.2.0-5.2.10, 5.3.0-5.3.9, 5.4.0-5.4.6, 5.5.0 - Denial of Service via OAuth 2.0 Authorization Request
CVSS 7.5
CVE-2021-34549 HIGH
Tor < 0.3.5.15 - Uncontrolled Resource Consumption via Circuit ID Hashing
CVSS 7.5
CVE-2021-33503 HIGH
urllib3 >=1.25.4 <1.26.5 - Denial of Service via Authority Component Regex Backtracking
CVSS 7.5
CVE-2021-32723 HIGH
Prism < 1.24.0 - Regular Expression Denial of Service in ASCIIDoc and ERB Highlighters
CVSS 7.4
CVE-2021-32722 MEDIUM
MediaWiki <48be7adb70568e20e961ea1cb70904454a671b1d - DoS
CVSS 6.5
CVE-2021-32823 LOW
bindata < 2.4.10 - Denial of Service via Slow Bit Class Creation
CVSS 3.7
CVE-2021-32699 MEDIUM
Pterodactyl Wings < 1.4.4 - Resource Exhaustion via Improper Container Process Limits
CVSS 6.5
CVE-2021-33824 HIGH
MOXA Mgate MB3180 2.1 Build 18113012 - Denial of Service via Incomplete HTTP Request
CVSS 7.5
CVE-2021-33822 HIGH
4GEE ROUTER HH70VB Firmware HH70_E1_02.00_22 - Denial of Service via Incomplete HTTP Request
CVSS 7.5
Details
Vulnerabilities 3,148
Exploit Likelihood High