CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
4,124 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 40 of 83
- CVE-2023-34150MEDIUMCVSS 6.5EG 6.52023-07-05
** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.
- CVE-2023-34166HIGHCVSS 7.5EG 7.52023-06-19
Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart.
- CVE-2023-3424HIGHCVSS 7.5EG 7.52023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service wa…
- CVE-2023-34324MEDIUMCVSS 4.9EG 4.92024-01-05
Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. …
- CVE-2023-34397HIGHCVSS 7.5EG 7.52025-02-13
Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be crashed.
- CVE-2023-34458HIGHCVSS 7.1EG 7.12023-07-13
mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's sender account nonc…
- CVE-2023-34462MEDIUMCVSS 6.5EG 6.52023-06-22
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handsha…
- CVE-2023-34612HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34613HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered sojo thru 1.1.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34614HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34615HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34616HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34617HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered genson thru 1.6 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-34872MEDIUMCVSS 5.5EG 5.52023-07-31
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
- CVE-2023-34969MEDIUMCVSS 6.5EG 6.52023-06-08
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivilege…
- CVE-2023-35053HIGHCVSS 7.5EG 7.52023-06-12
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
- CVE-2023-35110HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
- CVE-2023-35191MEDIUMCVSS 6.8EG 6.82024-03-14
Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of service via network access.
- CVE-2023-35298HIGHCVSS 7.5EG 7.52023-07-11
HTTP.sys Denial of Service Vulnerability
- CVE-2023-35329MEDIUMCVSS 6.5EG 6.52023-07-11
Windows Authentication Denial of Service Vulnerability
- CVE-2023-35339HIGHCVSS 7.5EG 7.52023-07-11
Windows CryptoAPI Denial of Service Vulnerability
- CVE-2023-35767HIGHCVSS 7.5EG 7.52023-11-08
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.
- CVE-2023-3585MEDIUMCVSS 4.3EG 4.32023-07-17
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
- CVE-2023-35909MEDIUMCVSS 5.3EG 5.32023-12-07
Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for W…
- CVE-2023-35920HIGHCVSS 7.5EG 7.52023-07-11
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3…
- CVE-2023-35921HIGHCVSS 7.5EG 7.52023-07-11
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3…
- CVE-2023-35925MEDIUMCVSS 6.2EG 6.22023-06-23
FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibility of bringing the …
- CVE-2023-3593MEDIUMCVSS 4.3EG 4.32023-07-17
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.
- CVE-2023-35945HIGHCVSS 7.5EG 7.52023-07-13
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In…
- CVE-2023-36038HIGHCVSS 8.2EG 8.22023-11-14
ASP.NET Core Denial of Service Vulnerability
- CVE-2023-36042MEDIUMCVSS 6.2EG 6.22023-11-14
Visual Studio Denial of Service Vulnerability
- CVE-2023-3614MEDIUMCVSS 4.3EG 4.32023-07-17
Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.
- CVE-2023-36161HIGHCVSS 7.5EG 7.52023-09-11
An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication.
- CVE-2023-3637MEDIUMCVSS 4.3EG 6.52023-07-25
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the us…
- CVE-2023-36431HIGHCVSS 7.5EG 7.52023-10-10
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2023-36435HIGHCVSS 7.5EG 7.52023-10-10
Microsoft QUIC Denial of Service Vulnerability
- CVE-2023-36478HIGHCVSS 7.5EG 7.52023-10-10
Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to ex…
- CVE-2023-36533HIGHCVSS 7.1EG 7.12023-08-08
Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.
- CVE-2023-36579HIGHCVSS 7.5EG 7.52023-10-10
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2023-36606HIGHCVSS 7.5EG 8.52023-10-10
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2023-36703HIGHCVSS 7.5EG 7.52023-10-10
DHCP Server Service Denial of Service Vulnerability
- CVE-2023-36799MEDIUMCVSS 6.5EG 6.52023-09-12
.NET Core and Visual Studio Denial of Service Vulnerability
- CVE-2023-36818MEDIUMCVSS 6.5EG 6.52023-07-14
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. The…
- CVE-2023-36841HIGHCVSS 7.5EG 7.52023-10-12
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in …
- CVE-2023-37014HIGHCVSS 7.5EG 7.52025-01-22
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field …
- CVE-2023-37022HIGHCVSS 7.5EG 7.52025-01-22
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to …
- CVE-2023-37140MEDIUMCVSS 5.5EG 5.52023-07-18
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount().
- CVE-2023-37141MEDIUMCVSS 5.5EG 5.52023-07-18
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray().
- CVE-2023-37142MEDIUMCVSS 5.5EG 5.52023-07-18
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().
- CVE-2023-37143MEDIUMCVSS 5.5EG 5.52023-07-18
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp().
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →