CWE-405 · 56 kayıt
Asymmetric Resource Consumption (Amplification)
Bu sınıftaki CVE’ler
56 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2019-11479İstismar yok | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.linux · linux kernel · CWE-405 | Yüksek7,5 | — | %91,7 | 18 Haz 2019 |
35İzleyin | CVE-2024-11187İstismar yok | Many records in the additional section cause CPU exhaustionisc · bind 9 · CWE-405 | Yüksek7,5 | — | %16,7 | 29 Oca 2025 |
34İzleyin | CVE-2026-25611İstismar yok | Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Servermongodb inc · mongodb server · CWE-405 | Yüksek8,7 | — | %0,6 | 10 Şub 2026 |
34İzleyin | CVE-2025-53633İstismar yok | Chall-Manager's scenario decoding process does not check for zip bombsctfer-io · chall-manager · CWE-405 | Yüksek8,7 | — | %0,5 | 10 Tem 2025 |
33İzleyin | CVE-2025-8677İstismar yok | Resource exhaustion via malformed DNSKEY handlingisc · bind 9 · CWE-405 | Yüksek7,5 | — | %10,7 | 22 Eki 2025 |
33İzleyin | CVE-2025-22166İstismar yok | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.atlassian · confluence data center · CWE-405 | Yüksek8,3 | — | %0,5 | 21 Eki 2025 |
31İzleyin | CVE-2021-38447İstismar yok | OCI OpenDDS Secure Amplificationobjectcomputing · opendds · CWE-405 | Yüksek7,5 | — | %2,1 | 5 May 2022 |
31İzleyin | CVE-2021-21359İstismar yok | Denial of Service in Page Error Handlingtypo3 · typo3 · CWE-405 | Yüksek7,5 | — | %1,7 | 22 Mar 2021 |
31İzleyin | CVE-2025-42874İstismar yok | Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)sap_se · sap netweaver (remote service for xcelsius) · CWE-405 | Yüksek7,9 | — | %0,5 | 9 Ara 2025 |
30İzleyin | CVE-2026-54874İstismar yok | Excessive Memory Use Buffering DTLS Records for a Future Epochopenssl · openssl · CWE-405 | Yüksek7,5 | — | %1,3 | 25 Ağu 2026 |
30İzleyin | CVE-2018-15492İstismar yok | A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.gemalto · sentinel license manager · CWE-405 | Yüksek7,5 | — | %1,2 | 17 Ağu 2018 |
30İzleyin | CVE-2026-47774İstismar yok | Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplificationenvoyproxy · envoy · CWE-405 | Yüksek7,5 | — | %1,1 | 17 Haz 2026 |
30İzleyin | CVE-2026-72914İstismar yok | Mastodon: Exhausting data by an unauthenticated request to the admin retention APImastodon · mastodon · CWE-405 | Yüksek7,5 | — | %0,8 | 10 Ağu 2026 |
30İzleyin | CVE-2024-45590Kavram kanıtı | body-parser vulnerable to denial of service when url encoding is enabledopenjsf · body-parser · CWE-405 | Yüksek7,5 | — | %0,8 | 10 Eyl 2024 |
30İzleyin | CVE-2025-30204İstismar yok | jwt-go allows excessive memory allocation during header parsinggolang-jwt · jwt · CWE-405 | Yüksek7,5 | — | %0,7 | 21 Mar 2025 |
30İzleyin | CVE-2024-55628İstismar yok | Suricata oversized resource names utilizing DNS name compression can lead to resource starvationoisf · suricata · CWE-405 | Yüksek7,5 | — | %0,7 | 6 Oca 2025 |
30İzleyin | CVE-2026-87011İstismar yok | Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutopenwebui · open webui · CWE-405 | Yüksek7,5 | — | %0,6 | 9 Eyl 2026 |
30İzleyin | CVE-2026-22775İstismar yok | devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parsesvelte · devalue · CWE-405 | Yüksek7,5 | — | %0,6 | 15 Oca 2026 |
30İzleyin | CVE-2026-22774İstismar yok | devalue vulnerable to denial of service due to memory exhaustion in devalue.parsesvelte · devalue · CWE-405 | Yüksek7,5 | — | %0,6 | 15 Oca 2026 |
30İzleyin | CVE-2023-2992İstismar yok | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered underlenovo · nextscale n1200 enclosure firmware · CWE-405 | Yüksek7,5 | — | %0,6 | 26 Haz 2023 |
30İzleyin | CVE-2024-39743İstismar yok | IBM MQ Container denial of serviceibm · mq operator · CWE-405 | Yüksek7,5 | — | %0,6 | 8 Tem 2024 |
30İzleyin | CVE-2024-34703İstismar yok | Botan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve Parametersrandombit · botan · CWE-405 | Yüksek7,5 | — | %0,5 | 30 Haz 2024 |
30İzleyin | CVE-2025-66564İstismar yok | Sigstore Timestamp Authority allocates excessive memory during request parsinglinuxfoundation · sigstore timestamp authority · CWE-405 | Yüksek7,5 | — | %0,4 | 4 Ara 2025 |
30İzleyin | CVE-2026-0485İstismar yok | Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platformsap · businessobjects business intelligence platform · CWE-405 | Yüksek7,5 | — | %0,4 | 10 Şub 2026 |
30İzleyin | CVE-2025-31987İstismar yok | HCL Connections Docs is vulnerable to a Denial of Service (DoS) attackhcltech · connections docs · CWE-405 | Yüksek7,5 | — | %0,2 | 14 Ağu 2025 |
- CVE-2019-1147957Planlayın
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.
YüksekCVSS 7,5İstismar yokEPSS %92linux · linux kernel18 Haz 2019
- CVE-2024-1118735İzleyin
Many records in the additional section cause CPU exhaustion
YüksekCVSS 7,5İstismar yokEPSS %17isc · bind 929 Oca 2025
- CVE-2026-2561134İzleyin
Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server
YüksekCVSS 8,7İstismar yokEPSS %1mongodb inc · mongodb server10 Şub 2026
- CVE-2025-5363334İzleyin
Chall-Manager's scenario decoding process does not check for zip bombs
YüksekCVSS 8,7İstismar yokEPSS %0ctfer-io · chall-manager10 Tem 2025
- CVE-2025-867733İzleyin
Resource exhaustion via malformed DNSKEY handling
YüksekCVSS 7,5İstismar yokEPSS %11isc · bind 922 Eki 2025
- CVE-2025-2216633İzleyin
This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.
YüksekCVSS 8,3İstismar yokEPSS %1atlassian · confluence data center21 Eki 2025
- CVE-2021-3844731İzleyin
OCI OpenDDS Secure Amplification
YüksekCVSS 7,5İstismar yokEPSS %2objectcomputing · opendds5 May 2022
- CVE-2021-2135931İzleyin
Denial of Service in Page Error Handling
YüksekCVSS 7,5İstismar yokEPSS %2typo3 · typo322 Mar 2021
- CVE-2025-4287431İzleyin
Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
YüksekCVSS 7,9İstismar yokEPSS %0sap_se · sap netweaver (remote service for xcelsius)9 Ara 2025
- CVE-2026-5487430İzleyin
Excessive Memory Use Buffering DTLS Records for a Future Epoch
YüksekCVSS 7,5İstismar yokEPSS %1openssl · openssl25 Ağu 2026
- CVE-2018-1549230İzleyin
A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.
YüksekCVSS 7,5İstismar yokEPSS %1gemalto · sentinel license manager17 Ağu 2018
- CVE-2026-4777430İzleyin
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
YüksekCVSS 7,5İstismar yokEPSS %1envoyproxy · envoy17 Haz 2026
- CVE-2026-7291430İzleyin
Mastodon: Exhausting data by an unauthenticated request to the admin retention API
YüksekCVSS 7,5İstismar yokEPSS %1mastodon · mastodon10 Ağu 2026
- CVE-2024-4559030İzleyin
body-parser vulnerable to denial of service when url encoding is enabled
YüksekCVSS 7,5Kavram kanıtıEPSS %1openjsf · body-parser10 Eyl 2024
- CVE-2025-3020430İzleyin
jwt-go allows excessive memory allocation during header parsing
YüksekCVSS 7,5İstismar yokEPSS %1golang-jwt · jwt21 Mar 2025
- CVE-2024-5562830İzleyin
Suricata oversized resource names utilizing DNS name compression can lead to resource starvation
YüksekCVSS 7,5İstismar yokEPSS %1oisf · suricata6 Oca 2025
- CVE-2026-8701130İzleyin
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
YüksekCVSS 7,5İstismar yokEPSS %1openwebui · open webui9 Eyl 2026
- CVE-2026-2277530İzleyin
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
YüksekCVSS 7,5İstismar yokEPSS %1svelte · devalue15 Oca 2026
- CVE-2026-2277430İzleyin
devalue vulnerable to denial of service due to memory exhaustion in devalue.parse
YüksekCVSS 7,5İstismar yokEPSS %1svelte · devalue15 Oca 2026
- CVE-2023-299230İzleyin
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under
YüksekCVSS 7,5İstismar yokEPSS %1lenovo · nextscale n1200 enclosure firmware26 Haz 2023
- CVE-2024-3974330İzleyin
IBM MQ Container denial of service
YüksekCVSS 7,5İstismar yokEPSS %1ibm · mq operator8 Tem 2024
- CVE-2024-3470330İzleyin
Botan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve Parameters
YüksekCVSS 7,5İstismar yokEPSS %1randombit · botan30 Haz 2024
- CVE-2025-6656430İzleyin
Sigstore Timestamp Authority allocates excessive memory during request parsing
YüksekCVSS 7,5İstismar yokEPSS %0linuxfoundation · sigstore timestamp authority4 Ara 2025
- CVE-2026-048530İzleyin
Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform
YüksekCVSS 7,5İstismar yokEPSS %0sap · businessobjects business intelligence platform10 Şub 2026
- CVE-2025-3198730İzleyin
HCL Connections Docs is vulnerable to a Denial of Service (DoS) attack
YüksekCVSS 7,5İstismar yokEPSS %0hcltech · connections docs14 Ağu 2025