VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 101 of 192
  • CVE-2020-35233MedMar 10, 2021
    risk 0.42cvss 6.5epss 0.01

    The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.

  • CVE-2021-27923HigMar 3, 2021
    risk 0.42cvss 7.5epss 0.03

    Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

  • CVE-2021-27922HigMar 3, 2021
    risk 0.42cvss 7.5epss 0.05

    Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

  • CVE-2021-27921HigMar 3, 2021
    risk 0.42cvss 7.5epss 0.03

    Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.

  • CVE-2021-23341HigFeb 18, 2021
    risk 0.42cvss 7.5epss 0.03

    The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.

  • CVE-2021-22553MedFeb 17, 2021
    risk 0.42cvss 6.5epss 0.00

    Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to…

  • CVE-2020-13949HigFeb 12, 2021
    risk 0.42cvss 7.5epss 0.07

    In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

  • CVE-2021-27191HigFeb 11, 2021
    risk 0.42cvss 7.5epss 0.02

    The get-ip-range package before 4.0.0 for Node.js is vulnerable to denial of service (DoS) if the range is untrusted input. An attacker could send a large range (such as 128.0.0.0/1) that causes resource exhaustion.

  • CVE-2021-21240HigFeb 8, 2021
    risk 0.42cvss 7.5epss 0.04

    httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2…

  • CVE-2021-21294HigFeb 2, 2021
    risk 0.42cvss 7.5epss 0.02

    Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead to a denial-of-service. Blaze-core, a library underlying http4s-blaze-server, accepts connections…

  • CVE-2021-21293HigFeb 2, 2021
    risk 0.42cvss 7.5epss 0.02

    blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are affected by a vulnerability in which unbounded connection acceptance leads to file handle exhaustion. Blaze, accepts connections…

  • CVE-2021-21254MedJan 29, 2021
    risk 0.42cvss 6.5epss 0.02

    CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to abuse link recognition…

  • CVE-2020-8293MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.02

    A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

  • CVE-2021-0215MedJan 15, 2021
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory leak occurs every time the 802.1X authenticator port interface flaps which can lead to other processes, such as the pfex process, responsible for packet forwarding, to crash and…

  • CVE-2020-36049HigJan 8, 2021
    risk 0.42cvss 7.5epss 0.03

    socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.

  • CVE-2020-36048HigJan 8, 2021
    risk 0.42cvss 7.5epss 0.03

    Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

  • CVE-2020-36066HigJan 5, 2021
    risk 0.42cvss 7.5epss 0.02

    GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.

  • CVE-2020-7771HigJan 4, 2021
    risk 0.42cvss 7.5epss 0.02

    The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.

  • CVE-2020-35857HigDec 31, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption.

  • CVE-2020-26289HigDec 28, 2020
    risk 0.42cvss 7.5epss 0.02

    date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.