CWE-400— Uncontrolled Resource Consumption (Denial of Service)
3,215 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 23 of 65
- CVE-2021-3821CRITICALCVSS 9.8EG 9.82022-12-12
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products.
- CVE-2021-3822HIGHCVSS 7.5EG 7.52021-09-27
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
- CVE-2021-38463HIGHCVSS 7.3EG 8.12021-10-22
The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functions.
- CVE-2021-38465HIGHCVSS 8.0EG 6.52021-10-22
The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp…
- CVE-2021-38566HIGHCVSS 7.5EG 7.52021-08-11
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows stack consumption during recursive processing of embedded XML nodes.
- CVE-2021-38788HIGHCVSS 7.5EG 7.52022-01-19
The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious apps can use the interface provided by the service to set the number of applications allowed to run in the background to 0…
- CVE-2021-38872HIGHCVSS 7.5EG 7.52022-05-17
IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force ID: 208348.
- CVE-2021-38951HIGHCVSS 7.5EG 7.52021-12-09
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CP…
- CVE-2021-38988MEDIUMCVSS 5.5EG 5.52022-03-07
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950.
- CVE-2021-38989MEDIUMCVSS 5.5EG 5.52022-03-07
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.
- CVE-2021-3908MEDIUMCVSS 5.9EG 5.92021-11-11
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
- CVE-2021-3909MEDIUMCVSS 4.4EG 4.42021-11-11
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a …
- CVE-2021-3912MEDIUMCVSS 4.2EG 4.22021-11-11
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
- CVE-2021-39123HIGHCVSS 7.5EG 7.52021-09-14
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpo…
- CVE-2021-39171MEDIUMCVSS 5.3EG 5.32021-08-27
Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payload can require transforms that consume significant system resources to process, thereby res…
- CVE-2021-39229HIGHCVSS 7.5EG 7.52021-09-20
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. In affected versions users who use Apprise granting them access to the IFTTT plugin (which just co…
- CVE-2021-39295HIGHCVSS 7.5EG 7.52023-04-15
In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.
- CVE-2021-39624MEDIUMCVSS 5.5EG 5.52022-03-16
In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: Andro…
- CVE-2021-39877HIGHCVSS 7.7EG 7.72021-10-04
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
- CVE-2021-39914LOWCVSS 3.1EG 4.32021-11-04
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user
- CVE-2021-39932MEDIUMCVSS 4.3EG 4.32021-12-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature coul…
- CVE-2021-39938LOWCVSS 3.1EG 3.12021-12-13
A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consu…
- CVE-2021-39939MEDIUMCVSS 6.5EG 6.52021-12-13
An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker t…
- CVE-2021-39942MEDIUMCVSS 4.3EG 4.32022-01-18
A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows low-privileged users to bypass …
- CVE-2021-40011HIGHCVSS 7.5EG 9.12022-01-10
There is an uncontrolled resource consumption vulnerability in the display module. Successful exploitation of this vulnerability may affect integrity.
- CVE-2021-40117HIGHCVSS 8.6EG 7.52021-10-27
A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …
- CVE-2021-40125MEDIUMCVSS 5.3EG 6.52021-10-27
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a …
- CVE-2021-4021HIGHCVSS 7.5EG 7.52022-02-24
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.
- CVE-2021-4022MEDIUMCVSS 5.5EG 5.52022-08-25
A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, d…
- CVE-2021-4040MEDIUMCVSS 5.3EG 5.32022-08-24
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sust…
- CVE-2021-40406HIGHCVSS 7.5EG 7.52022-01-28
A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP …
- CVE-2021-40606MEDIUMCVSS 5.5EG 5.52022-06-28
The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
- CVE-2021-41014HIGHCVSS 7.5EG 7.52021-12-08
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
- CVE-2021-41115MEDIUMCVSS 4.3EG 4.32021-10-07
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via arbitrary regular exp…
- CVE-2021-41118MEDIUMCVSS 5.3EG 5.32021-10-04
The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. In affected versions unsanitised input of regular expression date within the parameters of the D…
- CVE-2021-41119MEDIUMCVSS 5.3EG 5.32022-04-13
Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial of service attack via a crafted object causing a hash collision. This collision causes the server to spend at least quad…
- CVE-2021-41145HIGHCVSS 8.6EG 8.62021-10-25
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Den…
- CVE-2021-4115MEDIUMCVSS 5.5EG 5.52022-02-21
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied…
- CVE-2021-41167HIGHCVSS 7.5EG 7.52021-10-20
modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should li…
- CVE-2021-41168MEDIUMCVSS 6.5EG 6.52021-10-21
Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was found to be vulnerable to denial of service attacks to its reference table implementation. Ref…
- CVE-2021-41186MEDIUMCVSS 5.9EG 5.92021-10-29
Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerabi…
- CVE-2021-41229MEDIUMCVSS 4.3EG 4.32021-11-12
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause…
- CVE-2021-41546HIGHCVSS 7.5EG 7.52021-10-12
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM RO…
- CVE-2021-42075HIGHCVSS 7.5EG 7.52021-11-08
An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) does not correctly close file descriptors for established TCP connections. An unauthenticated remote attacker can thus …
- CVE-2021-42120MEDIUMCVSS 6.5EG 6.52021-11-30
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated remote attacker with Object Modification privileges to ins…
- CVE-2021-42219HIGHCVSS 7.5EG 7.52022-03-17
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.
- CVE-2021-42284MEDIUMCVSS 6.8EG 7.52021-11-10
Windows Hyper-V Denial of Service Vulnerability
- CVE-2021-42521HIGHCVSS 7.5EG 7.52022-08-25
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe …
- CVE-2021-42836HIGHCVSS 7.5EG 7.52021-10-22
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
- CVE-2021-43114HIGHCVSS 7.5EG 7.52021-11-09
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →