CWE-400— Uncontrolled Resource Consumption (Denial of Service)
3,215 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 41 of 65
- CVE-2023-51301HIGHCVSS 7.5EG 7.52025-02-19
A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS…
- CVE-2023-51314HIGHCVSS 7.5EG 7.52025-02-20
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (D…
- CVE-2023-51316HIGHCVSS 7.5EG 7.52025-02-20
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amoun…
- CVE-2023-51393MEDIUMCVSS 5.3EG 5.32024-02-23
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to…
- CVE-2023-5157HIGHCVSS 7.5EG 7.52023-09-27
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
- CVE-2023-51775MEDIUMCVSS 6.5EG 6.52024-02-29
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
- CVE-2023-51847HIGHCVSS 7.5EG 7.52024-06-06
An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.
- CVE-2023-5196MEDIUMCVSS 6.5EG 6.52023-09-29
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and pos…
- CVE-2023-52098HIGHCVSS 7.5EG 7.52024-01-16
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52113HIGHCVSS 7.5EG 7.52024-01-16
launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52340HIGHCVSS 7.5EG 7.52024-07-05
The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a r…
- CVE-2023-52355HIGHCVSS 7.5EG 7.52024-01-25
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smalle…
- CVE-2023-52425HIGHCVSS 7.5EG 7.52024-02-04
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
- CVE-2023-52602HIGHCVSS 7.8EG 7.82024-03-06
In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds Read in dtSearch Currently while searching for current page in the sorted entry table of the page there is a out of bound access. Added a bou…
- CVE-2023-52672MEDIUMCVSS 5.5EG 7.02024-05-17
In the Linux kernel, the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commit c73be61cede5 ("pipe: Add general notification queue support") a regression was introduced that would lock up resized …
- CVE-2023-5330MEDIUMCVSS 4.3EG 4.32023-10-09
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
- CVE-2023-5333MEDIUMCVSS 4.3EG 4.32023-10-09
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
- CVE-2023-53873HIGHCVSS 8.7EG 0.02025-12-15
SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhel…
- CVE-2023-5522MEDIUMCVSS 4.3EG 4.32023-10-17
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel.
- CVE-2023-5595MEDIUMCVSS 5.5EG 5.12023-10-16
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
- CVE-2023-5625MEDIUMCVSS 5.3EG 5.32023-11-01
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
- CVE-2023-5685HIGHCVSS 7.5EG 7.52024-03-22
A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).
- CVE-2023-5724HIGHCVSS 7.5EG 7.52023-10-25
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
- CVE-2023-5759HIGHCVSS 7.5EG 7.52023-11-08
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.
- CVE-2023-5825MEDIUMCVSS 6.5EG 6.52023-11-06
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD…
- CVE-2023-5870LOWCVSS 2.2EG 2.22023-12-10
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core e…
- CVE-2023-5871MEDIUMCVSS 5.3EG 5.32023-11-27
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
- CVE-2023-5876LOWCVSS 3.1EG 3.12023-11-02
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
- CVE-2023-5915MEDIUMCVSS 5.3EG 5.32023-12-01
A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation. This vulnerability may allow to a remote attacker to cause a denial-of-service condition to the FCN/FCJ control…
- CVE-2023-5969MEDIUMCVSS 5.3EG 5.32023-11-06
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
- CVE-2023-6117MEDIUMCVSS 5.7EG 5.72023-11-22
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.
- CVE-2023-6180MEDIUMCVSS 5.3EG 5.32023-12-05
The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory u…
- CVE-2023-6193MEDIUMCVSS 5.3EG 5.32023-12-12
quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient o…
- CVE-2023-6228LOWCVSS 3.3EG 5.52023-12-18
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
- CVE-2023-6277MEDIUMCVSS 6.5EG 7.52023-11-24
An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.
- CVE-2023-6450MEDIUMCVSS 5.5EG 5.52024-01-19
An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service.
- CVE-2023-6489MEDIUMCVSS 4.3EG 4.32024-04-12
A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service d…
- CVE-2023-6502MEDIUMCVSS 4.3EG 4.32024-05-23
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafte…
- CVE-2023-6596HIGHCVSS 7.5EG 7.52024-04-25
An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.
- CVE-2023-6678MEDIUMCVSS 4.3EG 4.32024-04-12
An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service u…
- CVE-2023-6681MEDIUMCVSS 5.3EG 5.32024-02-12
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount o…
- CVE-2023-6682MEDIUMCVSS 6.5EG 6.52024-05-14
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integra…
- CVE-2023-6688MEDIUMCVSS 6.5EG 6.52024-05-14
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.
- CVE-2023-6736MEDIUMCVSS 6.5EG 6.52024-02-07
An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a cli…
- CVE-2023-6910MEDIUMCVSS 6.5EG 6.52023-12-20
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
- CVE-2023-7258MEDIUMCVSS 4.8EG 4.82024-05-15
A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox.…
- CVE-2023-7326HIGHCVSS 8.7EG 0.02025-11-12
The Epson Stylus SX510W embedded web management service fails to properly handle consecutive ampersand characters in query parameters when accessing /PRESENTATION/HTML/TOP/INDEX.HTML. A remote attacker can send a malformed request that tri…
- CVE-2024-0026MEDIUMCVSS 5.5EG 4.72024-05-07
In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not nee…
- CVE-2024-0115MEDIUMCVSS 6.1EG 6.12024-08-12
NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vul…
- CVE-2024-0157MEDIUMCVSS 5.9EG 5.92024-04-12
Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a …
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →