CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
4,283 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 7 of 86
- CVE-2023-37379HIGHCVSS 8.1EG 8.12023-08-23
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exp…
- CVE-2023-21543HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2022-22145HIGHCVSS 8.1EG 8.12022-03-11
CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.0…
- CVE-2015-5600HIGHCVSS 8.1EG 8.12015-08-03
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct bru…
- CVE-2018-17281HIGHCVSS 7.5EG 8.12018-09-24
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk …
- CVE-2021-38463HIGHCVSS 7.3EG 8.12021-10-22
The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functions.
- CVE-2024-44169HIGHCVSS 5.5EG 8.12024-09-17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to c…
- CVE-2021-38465HIGHCVSS 8.0EG 8.02021-10-22
The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp…
- CVE-2024-5011HIGHCVSS 7.5EG 8.02024-06-25
In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.
- CVE-2018-16843HIGHCVSS 7.5EG 8.02018-11-07
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'ht…
- CVE-2026-35266HIGHCVSS 7.9EG 7.92026-05-28
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle RES…
- CVE-2023-3364HIGHCVSS 7.5EG 7.92023-08-02
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was …
- CVE-2026-55266HIGHCVSS 7.8EG 7.82026-10-05
In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2026-83968HIGHCVSS 7.8EG 7.82026-09-08
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-21500HIGHCVSS 7.8EG 7.82026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the XML calculator macro expan…
- CVE-2025-48615HIGHCVSS 7.8EG 7.82025-12-08
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2024-39479HIGHCVSS 7.8EG 7.82024-07-05
In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon and hwmon drvdata (on which hwmon depends) are device managed resources, the expectation, on device unbind, is that hwmon…
- CVE-2022-28657HIGHCVSS 7.8EG 7.82024-06-04
Apport does not disable python crash handler before entering chroot
- CVE-2024-26723HIGHCVSS 7.8EG 7.82024-04-03
In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix crash when adding interface under a lag There is a crash when adding one of the lan966x interfaces under a lag interface. The issue can be reproduced like t…
- CVE-2023-52602HIGHCVSS 7.8EG 7.82024-03-06
In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds Read in dtSearch Currently while searching for current page in the sorted entry table of the page there is a out of bound access. Added a bou…
- CVE-2021-47010HIGHCVSS 7.8EG 7.82024-02-28
In the Linux kernel, the following vulnerability has been resolved: net: Only allow init netns to set default tcp cong to a restricted algo tcp_set_default_congestion_control() is netns-safe in that it writes to &net->ipv4.tcp_congestion…
- CVE-2022-47696HIGHCVSS 7.8EG 7.82023-08-22
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.
- CVE-2022-47695HIGHCVSS 7.8EG 7.82023-08-22
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c.
- CVE-2023-21110HIGHCVSS 7.8EG 7.82023-05-15
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2023-1654HIGHCVSS 7.8EG 7.82023-03-27
Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.
- CVE-2023-20911HIGHCVSS 7.8EG 7.82023-03-24
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2022-20491HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20488HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20487HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20486HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20485HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20484HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20480HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20479HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20478HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-2962HIGHCVSS 7.8EG 7.82022-09-13
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO address. This can cause …
- CVE-2021-36924HIGHCVSS 7.8EG 7.82021-11-02
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted D…
- CVE-2021-30742HIGHCVSS 7.8EG 7.82021-09-08
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted audio file may lead to arbitrary code execution.
- CVE-2021-25174HIGHCVSS 7.8EG 7.82021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash,…
- CVE-2019-10547HIGHCVSS 7.8EG 7.82020-04-16
When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Indu…
- CVE-2019-9587HIGHCVSS 7.8EG 7.82019-03-06
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation f…
- CVE-2017-14180HIGHCVSS 7.8EG 7.82018-02-02
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or po…
- CVE-2017-14179HIGHCVSS 7.8EG 7.82018-02-02
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gai…
- CVE-2017-14177HIGHCVSS 7.8EG 7.82018-02-02
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain ro…
- CVE-2017-7132HIGHCVSS 7.8EG 7.82017-11-13
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via …
- CVE-2017-13825HIGHCVSS 7.8EG 7.82017-11-13
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a …
- CVE-2017-8247HIGHCVSS 7.8EG 7.82017-09-21
In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once. This would lead to get_pid being called more than on…
- CVE-2017-8264HIGHCVSS 7.8EG 7.82017-08-11
A userspace process can cause a Denial of Service in the camera driver in all Qualcomm products with Android releases from CAF using the Linux kernel.
- CVE-2017-2535HIGHCVSS 7.8EG 7.82017-05-22
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers to conduct sandbox-escape attacks or cause a denial of service (resource consumption) via…
- CVE-2019-5645HIGHCVSS 7.5EG 7.82020-09-01
By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions fr…
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →