CWE-400 · 3.675 kayıt
Kontrolsüz kaynak tüketimi
Neden olur?
İç içe yapıları çözümleyen kod derinlik ya da boyut sınırı koymuyor. Küçük bir girdi orantısız işlem yüküne dönüşebilir.
Hatalı ve düzeltilmiş kod
Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.
Hatalı
function expand(node) { return node.children.map(expand);}Düzeltilmiş
const MAX_DEPTH = 32;function expand(node, depth = 0) { if (depth > MAX_DEPTH) throw new Error("çok derin"); return node.children.map((c) => expand(c, depth + 1));}Nasıl önlenir?
- 01Çözümleyicilerde derinlik, uzunluk ve süre sınırı belirleyin.
- 02Kullanıcı girdisini kayda yazmadan önce kısaltın.
- 03İşlemci ve bellek kullanımına uyarı eşiği koyun.
Bu sınıftaki CVE’ler
3.677 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
65Bu hafta | CVE-2020-3566Silahlaştırılmış | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilitycisco · ios xr · CWE-400 | Yüksek8,6 | KEV | %3,7 | 29 Ağu 2020 |
65Bu hafta | CVE-2020-3569Silahlaştırılmış | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilitiescisco · ios xr · CWE-400 | Yüksek8,6 | KEV | %3,3 | 22 Eyl 2020 |
64Bu hafta | CVE-2023-38180Silahlaştırılmış | .NET and Visual Studio Denial of Service Vulnerabilitymicrosoft · .net · CWE-400 | Yüksek7,5 | KEV | %14,0 | 8 Ağu 2023 |
61Bu hafta | CVE-2011-3192Silahlaştırılmış | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a deniapache · http server · CWE-400 | Yüksek7,8 | — | %98,8 | 29 Ağu 2011 |
61Bu hafta | CVE-2026-28318Silahlaştırılmış | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerabilitysolarwinds · serv-u · CWE-400 | Yüksek7,5 | KEV | %1,9 | 4 Haz 2026 |
60Bu hafta | CVE-2026-45498Silahlaştırılmış | Microsoft Defender Denial of Service Vulnerabilitymicrosoft · defender antimalware platform · CWE-400 | Yüksek7,5 | KEV | %1,3 | 20 May 2026 |
58Planlayın | CVE-2023-45288Kavram kanıtı | HTTP/2 CONTINUATION flood in net/httpgo standard library · net/http · CWE-400 | Yüksek7,5 | — | %92,0 | 4 Nis 2024 |
56Planlayın | CVE-2018-1000115Silahlaştırılmış | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDPmemcached · memcached · CWE-400 | Yüksek7,5 | — | %88,1 | 5 Mar 2018 |
56Planlayın | CVE-2019-9515İstismar yok | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %87,4 | 13 Ağu 2019 |
55Planlayın | CVE-2019-9512İstismar yok | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %83,4 | 13 Ağu 2019 |
55Planlayın | CVE-2019-9514İstismar yok | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %82,8 | 13 Ağu 2019 |
55Planlayın | CVE-2023-50868Kavram kanıtı | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | Yüksek7,5 | — | %81,7 | 14 Şub 2024 |
54Planlayın | CVE-2019-9513İstismar yok | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Yüksek7,5 | — | %81,6 | 13 Ağu 2019 |
54Planlayın | CVE-2023-28342İstismar yok | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.zohocorp · manageengine adselfservice plus · CWE-400 | Yüksek7,5 | — | %78,3 | 5 Nis 2023 |
54Planlayın | CVE-2004-1464Silahlaştırılmış | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafcisco · ios · CWE-400 | Orta5,9 | KEV | %4,8 | 31 Ara 2004 |
53Planlayın | CVE-2021-21341Kavram kanıtı | XStream can cause a Denial of Servicexstream · xstream · CWE-400 | Yüksek7,5 | — | %77,8 | 22 Mar 2021 |
53Planlayın | CVE-2003-0714Silahlaştırılmış | The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) microsoft · exchange server · CWE-400 | Yüksek7,5 | — | %77,6 | 17 Kas 2003 |
52Planlayın | CVE-2021-22883İstismar yok | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an nodejs · node.js · CWE-400 | Yüksek7,5 | — | %74,4 | 3 Mar 2021 |
52Planlayın | CVE-2018-5390İstismar yok | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can linux · linux kernel · CWE-400 | Yüksek7,5 | — | %73,7 | 6 Ağu 2018 |
52Planlayın | CVE-2022-29885Kavram kanıtı | EncryptInterceptor does not provide complete protection on insecure networksapache · tomcat · CWE-400 | Yüksek7,5 | — | %73,5 | 12 May 2022 |
52Planlayın | CVE-2019-0199İstismar yok | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS framesapache · tomcat · CWE-400 | Yüksek7,5 | — | %72,9 | 10 Nis 2019 |
52Planlayın | CVE-2017-3144İstismar yok | Failure to properly clean up closed OMAPI connections can exhaust available socketsisc · dhcp · CWE-400 | Yüksek7,5 | — | %72,7 | 16 Oca 2019 |
52Planlayın | CVE-2018-6389Kavram kanıtı | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registwordpress · wordpress · CWE-400 | Yüksek7,5 | — | %72,7 | 6 Şub 2018 |
51Planlayın | CVE-2023-43622Kavram kanıtı | Apache HTTP Server: DoS in HTTP/2 with initial windows size 0apache · http server · CWE-400 | Yüksek7,5 | — | %70,6 | 23 Eki 2023 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2020-356665Bu hafta
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %4cisco · ios xr29 Ağu 2020
- CVE-2020-356965Bu hafta
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %3cisco · ios xr22 Eyl 2020
- CVE-2023-3818064Bu hafta
.NET and Visual Studio Denial of Service Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %14microsoft · .net8 Ağu 2023
- CVE-2011-319261Bu hafta
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a deni
YüksekCVSS 7,8SilahlaştırılmışEPSS %99apache · http server29 Ağu 2011
- CVE-2026-2831861Bu hafta
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %2solarwinds · serv-u4 Haz 2026
- CVE-2026-4549860Bu hafta
Microsoft Defender Denial of Service Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %1microsoft · defender antimalware platform20 May 2026
- CVE-2023-4528858Planlayın
HTTP/2 CONTINUATION flood in net/http
YüksekCVSS 7,5Kavram kanıtıEPSS %92go standard library · net/http4 Nis 2024
- CVE-2018-100011556Planlayın
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP
YüksekCVSS 7,5SilahlaştırılmışEPSS %88memcached · memcached5 Mar 2018
- CVE-2019-951556Planlayın
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %87apple · swiftnio13 Ağu 2019
- CVE-2019-951255Planlayın
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %83apple · swiftnio13 Ağu 2019
- CVE-2019-951455Planlayın
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %83apple · swiftnio13 Ağu 2019
- CVE-2023-5086855Planlayın
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
YüksekCVSS 7,5Kavram kanıtıEPSS %82netapp · hci baseboard management controller14 Şub 2024
- CVE-2019-951354Planlayın
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
YüksekCVSS 7,5İstismar yokEPSS %82apple · swiftnio13 Ağu 2019
- CVE-2023-2834254Planlayın
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
YüksekCVSS 7,5İstismar yokEPSS %78zohocorp · manageengine adselfservice plus5 Nis 2023
- CVE-2004-146454Planlayın
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a craf
OrtaCVSS 5,9KEVSilahlaştırılmışEPSS %5cisco · ios31 Ara 2004
- CVE-2021-2134153Planlayın
XStream can cause a Denial of Service
YüksekCVSS 7,5Kavram kanıtıEPSS %78xstream · xstream22 Mar 2021
- CVE-2003-071453Planlayın
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion)
YüksekCVSS 7,5SilahlaştırılmışEPSS %78microsoft · exchange server17 Kas 2003
- CVE-2021-2288352Planlayın
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an
YüksekCVSS 7,5İstismar yokEPSS %74nodejs · node.js3 Mar 2021
- CVE-2018-539052Planlayın
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can
YüksekCVSS 7,5İstismar yokEPSS %74linux · linux kernel6 Ağu 2018
- CVE-2022-2988552Planlayın
EncryptInterceptor does not provide complete protection on insecure networks
YüksekCVSS 7,5Kavram kanıtıEPSS %73apache · tomcat12 May 2022
- CVE-2019-019952Planlayın
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames
YüksekCVSS 7,5İstismar yokEPSS %73apache · tomcat10 Nis 2019
- CVE-2017-314452Planlayın
Failure to properly clean up closed OMAPI connections can exhaust available sockets
YüksekCVSS 7,5İstismar yokEPSS %73isc · dhcp16 Oca 2019
- CVE-2018-638952Planlayın
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist
YüksekCVSS 7,5Kavram kanıtıEPSS %73wordpress · wordpress6 Şub 2018
- CVE-2023-4362251Planlayın
Apache HTTP Server: DoS in HTTP/2 with initial windows size 0
YüksekCVSS 7,5Kavram kanıtıEPSS %71apache · http server23 Eki 2023