CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
4,281 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 1 of 86
- CVE-2021-44228CRITICALCVSS 10.0EG 10.0⚠ KEV2021-12-10
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoin…
- CVE-2022-0028CRITICALCVSS 8.6EG 9.0⚠ KEV2022-08-10
A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hard…
- CVE-2020-3569CRITICALCVSS 8.6EG 9.0⚠ KEV2020-09-23
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) p…
- CVE-2020-3566CRITICALCVSS 8.6EG 9.0⚠ KEV2020-08-29
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insuffi…
- CVE-2020-9859CRITICALCVSS 7.8EG 9.0⚠ KEV2020-06-05
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbi…
- CVE-2026-28318CRITICALCVSS 7.5EG 9.0⚠ KEV2026-06-04
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust…
- CVE-2026-45498CRITICALCVSS 7.5EG 9.0⚠ KEV2026-05-20
Microsoft Defender Denial of Service Vulnerability
- CVE-2023-44487CRITICALCVSS 7.5EG 9.0⚠ KEV2023-10-10
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- CVE-2023-38180CRITICALCVSS 7.5EG 9.0⚠ KEV2023-08-08
.NET and Visual Studio Denial of Service Vulnerability
- CVE-2017-12237CRITICALCVSS 7.5EG 9.0⚠ KEV2017-09-29
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a …
- CVE-2004-1464CRITICALCVSS 5.9EG 9.0⚠ KEV2004-12-31
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.
- CVE-2024-4549CRITICALCVSS 7.5EG 10.02024-05-06
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.
- CVE-2026-60719CRITICALCVSS 9.9EG 9.92026-07-21
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged att…
- CVE-2026-46775CRITICALCVSS 9.9EG 9.92026-05-28
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST …
- CVE-2026-30141CRITICALCVSS 9.8EG 9.82026-06-09
An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.
- CVE-2025-70327CRITICALCVSS 9.8EG 9.82026-02-23
TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through Cst…
- CVE-2025-61303CRITICALCVSS 9.8EG 9.82025-10-20
Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade detection and cause denial-o…
- CVE-2025-59403CRITICALCVSS 9.8EG 9.82025-10-02
The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoi…
- CVE-2025-43193CRITICALCVSS 9.8EG 9.82025-07-30
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.
- CVE-2025-24269CRITICALCVSS 9.8EG 9.82025-03-31
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termination.
- CVE-2025-24264CRITICALCVSS 9.8EG 9.82025-03-31
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may l…
- CVE-2025-24260CRITICALCVSS 9.8EG 9.82025-03-31
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perform a denial-of-service.
- CVE-2025-24247CRITICALCVSS 9.8EG 9.82025-03-31
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker may be able to cause unexpected app termination.
- CVE-2025-24211CRITICALCVSS 9.8EG 9.82025-03-31
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafte…
- CVE-2025-24190CRITICALCVSS 9.8EG 9.82025-03-31
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a malic…
- CVE-2025-24126CRITICALCVSS 9.8EG 9.82025-01-27
An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to corrupt proce…
- CVE-2024-45166CRITICALCVSS 9.8EG 9.82024-08-22
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Deni…
- CVE-2024-39462CRITICALCVSS 9.8EG 9.82024-06-25
In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct…
- CVE-2022-48716CRITICALCVSS 9.8EG 9.82024-06-20
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in mixer->reg, which is not same as port id. port id should be derived from chan_i…
- CVE-2024-36543CRITICALCVSS 9.8EG 9.82024-06-17
Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connec…
- CVE-2024-25718CRITICALCVSS 9.8EG 9.82024-02-11
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.
- CVE-2023-41294CRITICALCVSS 9.8EG 9.82023-09-25
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
- CVE-2023-28507CRITICALCVSS 9.8EG 9.82023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memor…
- CVE-2021-3821CRITICALCVSS 9.8EG 9.82022-12-12
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products.
- CVE-2013-20004CRITICALCVSS 9.8EG 9.82022-02-06
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target mu…
- CVE-2021-1275CRITICALCVSS 9.8EG 9.82021-05-06
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privil…
- CVE-2017-9104CRITICALCVSS 9.8EG 9.82020-06-18
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
- CVE-2019-14901CRITICALCVSS 9.8EG 9.82019-11-29
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute a…
- CVE-2019-10750CRITICALCVSS 9.8EG 9.82019-08-23
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
- CVE-2019-10747CRITICALCVSS 9.8EG 9.82019-08-23
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.
- CVE-2019-2259CRITICALCVSS 9.8EG 9.82019-06-14
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Sn…
- CVE-2018-11936CRITICALCVSS 9.8EG 9.82019-05-24
Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads to out of bound memory access. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivit…
- CVE-2019-10952CRITICALCVSS 9.8EG 9.82019-05-01
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5…
- CVE-2018-19282CRITICALCVSS 9.8EG 9.82019-04-04
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a w…
- CVE-2018-16492CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
- CVE-2018-16491CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
- CVE-2018-16489CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
- CVE-2018-16486CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
- CVE-2015-4412CRITICALCVSS 9.8EG 9.82018-02-05
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.
- CVE-2017-1000378CRITICALCVSS 9.8EG 9.82017-06-19
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts…
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →