VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 102 of 192
  • CVE-2020-27722MedDec 24, 2020
    risk 0.42cvss 6.5epss 0.01

    In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption.

  • CVE-2020-27724MedDec 24, 2020
    risk 0.42cvss 6.5epss 0.01

    In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending specially-crafted…

  • CVE-2020-5682HigDec 16, 2020
    risk 0.42cvss 7.5epss 0.02

    Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier…

  • CVE-2020-35380HigDec 15, 2020
    risk 0.42cvss 7.5epss 0.02

    GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.

  • CVE-2020-7791HigDec 11, 2020
    risk 0.42cvss 7.5epss 0.03

    This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.

  • CVE-2020-7793HigDec 11, 2020
    risk 0.42cvss 7.5epss 0.04

    The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

  • CVE-2020-27813HigDec 2, 2020
    risk 0.42cvss 7.5epss 0.02

    An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

  • CVE-2020-7754HigOct 27, 2020
    risk 0.42cvss 7.5epss 0.03

    This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

  • CVE-2020-1689MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in a Virtual Chassis configuration, receipt of a stream of specific layer 2 frames can cause high CPU load, which could lead to traffic interruption. This issue does not occur when the device is…

  • CVE-2020-1687MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in (Ethernet VPN) EVPN-(Virtual Extensible LAN) VXLAN configuration, receipt of a stream of specific VXLAN encapsulated layer 2 frames can cause high CPU load, which could lead to network protocol…

  • CVE-2020-1678MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.00

    On Juniper Networks Junos OS and Junos OS Evolved platforms with EVPN configured, receipt of specific BGP packets causes a slow memory leak. If the memory is exhausted the rpd process might crash. If the issue occurs, the memory leak could be seen by executing the "show task…

  • CVE-2020-1670MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX4300 Series, receipt of a stream of specific IPv4 packets can cause Routing Engine (RE) high CPU load, which could lead to network protocol operation issue and traffic interruption. This specific packets can originate only from within the broadcast domain…

  • CVE-2020-1668MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX2300 Series, receipt of a stream of specific multicast packets by the layer2 interface can cause high CPU load, which could lead to traffic interruption. This issue occurs when multicast packets are received by the layer 2 interface. To check if the device…

  • CVE-2020-11645MedOct 15, 2020
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to limit availability of GateManager instances.

  • CVE-2020-3543MedOct 8, 2020
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to…

  • CVE-2019-20922HigSep 30, 2020
    risk 0.42cvss 7.5epss 0.04

    Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

  • CVE-2020-3487MedSep 24, 2020
    risk 0.42cvss 6.5epss 0.00

    Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS)…

  • CVE-2020-3428MedSep 24, 2020
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the WLAN Local Profiling feature of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to…

  • CVE-2020-7733HigSep 16, 2020
    risk 0.42cvss 7.5epss 0.04

    The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.

  • CVE-2020-3505MedAug 26, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to…