CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
4,283 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 5 of 86
- CVE-2020-3304HIGHCVSS 8.6EG 8.62020-10-21
A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, result…
- CVE-2020-3560HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specif…
- CVE-2020-3559HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the A…
- CVE-2020-3527HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit th…
- CVE-2020-3510HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affe…
- CVE-2020-3414HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in the packet processing of Cisco IOS XE Software for Cisco 4461 Integrated Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) cond…
- CVE-2020-3408HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in the Split DNS feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabi…
- CVE-2020-3351HIGHCVSS 8.6EG 8.62020-07-16
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of fields in Cisco SD-WAN peering messages that…
- CVE-2020-3203HIGHCVSS 8.6EG 8.62020-06-03
A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory l…
- CVE-2020-8616HIGHCVSS 8.6EG 8.62020-05-19
A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large…
- CVE-2020-3196HIGHCVSS 8.6EG 8.62020-05-06
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker …
- CVE-2020-3189HIGHCVSS 8.6EG 8.62020-05-06
A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unex…
- CVE-2020-3175HIGHCVSS 8.6EG 8.62020-02-26
A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The v…
- CVE-2019-16022HIGHCVSS 8.6EG 8.62020-01-26
Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vu…
- CVE-2019-16020HIGHCVSS 8.6EG 8.62020-01-26
Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vu…
- CVE-2019-15256HIGHCVSS 8.6EG 8.62019-10-02
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reloa…
- CVE-2019-10942HIGHCVSS 8.6EG 8.62019-08-13
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X204RNA (HSR) (All versi…
- CVE-2019-1873HIGHCVSS 8.6EG 8.62019-07-10
A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vu…
- CVE-2019-1814HIGHCVSS 8.6EG 8.62019-05-16
A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on system memory, which i…
- CVE-2019-1703HIGHCVSS 8.6EG 8.62019-05-03
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop proces…
- CVE-2018-15388HIGHCVSS 8.6EG 8.62019-05-03
A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affe…
- CVE-2019-1737HIGHCVSS 8.6EG 8.62019-03-27
A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE software could allow an unauthenticated, remote attacker to cause an interface wedge and an eventual denial of service (Do…
- CVE-2018-15377HIGHCVSS 8.6EG 8.62018-10-05
A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak on an af…
- CVE-2018-16132HIGHCVSS 8.6EG 8.62018-08-29
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to ex…
- CVE-2018-0418HIGHCVSS 8.6EG 8.62018-08-15
A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affe…
- CVE-2018-0410HIGHCVSS 8.6EG 8.62018-08-15
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affecte…
- CVE-2018-0233HIGHCVSS 8.6EG 8.62018-04-19
A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive…
- CVE-2018-0230HIGHCVSS 8.6EG 8.62018-04-19
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected devic…
- CVE-2018-0086HIGHCVSS 8.6EG 8.62018-01-18
A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to mal…
- CVE-2017-17051HIGHCVSS 8.6EG 8.62017-12-05
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of servic…
- CVE-2017-12293HIGHCVSS 8.6EG 8.62017-10-19
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made…
- CVE-2017-9627HIGHCVSS 8.6EG 8.62017-07-07
An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the mem…
- CVE-2016-6171HIGHCVSS 8.6EG 8.62017-02-09
Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.
- CVE-2015-1779HIGHCVSS 8.6EG 8.62016-01-12
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
- CVE-2024-20351HIGHCVSS 7.5EG 8.62024-10-23
A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network…
- CVE-2023-43622HIGHCVSS 7.5EG 8.62023-10-23
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well …
- CVE-2022-1797HIGHCVSS 6.8EG 8.62022-06-02
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unava…
- CVE-2017-15119HIGHCVSS 5.8EG 8.62018-07-27
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request…
- CVE-2026-55108HIGHCVSS 8.5EG 8.52026-08-28
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, Get…
- CVE-2023-36606HIGHCVSS 7.5EG 8.52023-10-10
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2020-27223HIGHCVSS 5.2EG 8.52021-02-26
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of…
- CVE-2024-27529HIGHCVSS 8.4EG 8.42024-11-08
wasm3 139076a contains memory leaks in Read_utf8.
- CVE-2024-38384HIGHCVSS 8.4EG 8.42024-06-24
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from reorder of WRITE ->lqueued __blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start is being executed. If WRI…
- CVE-2021-47313HIGHCVSS 8.4EG 8.42024-05-21
In the Linux kernel, the following vulnerability has been resolved: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init It's a classic example of memleak, we allocate something, we fail and never free the resources. Make sure …
- CVE-2024-35948HIGHCVSS 8.4EG 8.42024-05-20
In the Linux kernel, the following vulnerability has been resolved: bcachefs: Check for journal entries overruning end of sb clean section Fix a missing bounds check in superblock validation. Note that we don't yet have repair code for …
- CVE-2021-0180HIGHCVSS 8.4EG 8.42021-11-17
Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privilege escalation via local access.
- CVE-2024-26212HIGHCVSS 7.5EG 8.42024-04-09
DHCP Server Service Denial of Service Vulnerability
- CVE-2023-24580HIGHCVSS 7.5EG 8.42023-02-15
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open file…
- CVE-2019-15226HIGHCVSS 7.5EG 8.42019-10-09
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The implementation in versions 1.10.0 through 1.11.1 for HTTP/1.x …
- CVE-2026-60582HIGHCVSS 8.3EG 8.32026-07-21
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with net…
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →