CWE-400— Uncontrolled Resource Consumption (Denial of Service)
3,215 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 34 of 65
- CVE-2023-22664HIGHCVSS 7.5EG 7.52023-02-01
On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cau…
- CVE-2023-22792HIGHCVSS 7.5EG 7.52023-02-09
A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a specially crafted X_FORWARDED_HOST header can cause the regular expression engine to enter a…
- CVE-2023-22795HIGHCVSS 7.5EG 7.52023-02-09
A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastroph…
- CVE-2023-22796HIGHCVSS 7.5EG 7.52023-02-09
A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This ca…
- CVE-2023-22799HIGHCVSS 7.5EG 7.52023-02-09
A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release sh…
- CVE-2023-22819MEDIUMCVSS 4.9EG 4.92024-02-05
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Weste…
- CVE-2023-22874MEDIUMCVSS 5.5EG 5.52023-05-05
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.
- CVE-2023-2295HIGHCVSS 7.5EG 7.52023-05-17
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a…
- CVE-2023-23009MEDIUMCVSS 6.5EG 7.52023-02-21
Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.
- CVE-2023-23296MEDIUMCVSS 6.5EG 6.52023-02-23
Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.
- CVE-2023-23396MEDIUMCVSS 6.5EG 6.52023-03-14
Microsoft Excel Denial of Service Vulnerability
- CVE-2023-23411MEDIUMCVSS 6.5EG 6.52023-03-14
Windows Hyper-V Denial of Service Vulnerability
- CVE-2023-23447HIGHCVSS 7.5EG 7.52023-05-15
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing…
- CVE-2023-23524HIGHCVSS 7.5EG 7.52023-02-27
A denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, watchOS 9.3.1, macOS Ventura 13.2.1. Processing a maliciously crafted certificate may lead to a denia…
- CVE-2023-23552HIGHCVSS 7.5EG 7.52023-02-01
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed r…
- CVE-2023-23590HIGHCVSS 7.5EG 7.52023-01-15
Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote attackers to cause a denial of service (device restart) via an unauthenticated API request. The attacker must be on the same network as the device.
- CVE-2023-23616LOWCVSS 3.5EG 3.52023-01-28
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason prov…
- CVE-2023-23625MEDIUMCVSS 5.9EG 5.92023-02-09
go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can the…
- CVE-2023-23631MEDIUMCVSS 5.9EG 5.92023-02-09
github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot to 1.5.2 trying to read malformed HAMT sharded directories can cause panics and virtual mem…
- CVE-2023-23689MEDIUMCVSS 5.3EG 7.52023-02-28
Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains an uncontrolled resource consumption vulnerability. This may allow an unauthenticated network host to impair built-in …
- CVE-2023-23925HIGHCVSS 8.6EG 8.62023-02-03
Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy match operation (EXIST), where it is used to build a regular expression. This may result in a Regular ex…
- CVE-2023-24534HIGHCVSS 7.5EG 7.52023-04-06
HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME…
- CVE-2023-24536HIGHCVSS 7.5EG 7.52023-04-06
Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multi…
- CVE-2023-24545HIGHCVSS 7.5EG 7.52023-04-12
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough …
- CVE-2023-24574HIGHCVSS 7.5EG 7.52023-02-02
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication component. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to u…
- CVE-2023-24580HIGHCVSS 7.5EG 7.52023-02-15
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open file…
- CVE-2023-24594MEDIUMCVSS 5.3EG 5.32023-05-03
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu…
- CVE-2023-24620MEDIUMCVSS 5.5EG 5.52023-08-25
An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small Y…
- CVE-2023-24824MEDIUMCVSS 5.3EG 5.32023-03-31
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers q…
- CVE-2023-24860HIGHCVSS 7.5EG 7.52023-04-11
Microsoft Defender Denial of Service Vulnerability
- CVE-2023-24862MEDIUMCVSS 5.5EG 5.52023-03-14
Windows Secure Channel Denial of Service Vulnerability
- CVE-2023-25151HIGHCVSS 7.5EG 7.52023-02-08
opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements …
- CVE-2023-25179MEDIUMCVSS 5.0EG 5.02023-05-10
Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-25568HIGHCVSS 8.2EG 8.22023-05-10
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is able allocate arbitrary many bytes in the Bitswap server, those allocations are lasting eve…
- CVE-2023-25618MEDIUMCVSS 6.5EG 6.52023-03-14
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authentica…
- CVE-2023-25769MEDIUMCVSS 5.5EG 5.52024-02-14
Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-25774HIGHCVSS 7.5EG 7.52023-10-12
A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious pa…
- CVE-2023-25816MEDIUMCVSS 4.3EG 4.32023-02-25
Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation th…
- CVE-2023-25949MEDIUMCVSS 5.5EG 5.52023-11-14
Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-26044MEDIUMCVSS 5.3EG 5.32023-05-17
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when processing large HT…
- CVE-2023-26048MEDIUMCVSS 5.3EG 5.32023-04-18
Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRequest.getParts()` may cause `…
- CVE-2023-26104HIGHCVSS 7.5EG 7.52023-02-25
All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
- CVE-2023-26141HIGHCVSS 7.5EG 7.52023-09-14
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will…
- CVE-2023-26144MEDIUMCVSS 5.3EG 5.32023-09-20
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an att…
- CVE-2023-26151MEDIUMCVSS 5.3EG 5.32023-10-03
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.
- CVE-2023-26157MEDIUMCVSS 5.5EG 5.52024-01-02
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
- CVE-2023-26432MEDIUMCVSS 4.3EG 4.32023-06-20
When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually …
- CVE-2023-26433MEDIUMCVSS 4.3EG 4.32023-06-20
When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually …
- CVE-2023-26434MEDIUMCVSS 4.3EG 4.32023-06-20
When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually …
- CVE-2023-26437LOWCVSS 3.4EG 5.32023-04-04
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →