VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 104 of 192
  • CVE-2020-1700MedFeb 7, 2020
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of…

  • CVE-2019-20446MedFeb 2, 2020
    risk 0.42cvss 6.5epss 0.02

    In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

  • CVE-2020-3131MedJan 26, 2020
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the client to crash, resulting in a denial of service (DoS) condition. The attacker needs a valid developer account to exploit this vulnerability. The vulnerability…

  • CVE-2019-16018MedJan 26, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a…

  • CVE-2012-4863MedJan 23, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulnerability

  • CVE-2020-1600MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.01

    In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability in the Routing Protocol Daemon (RPD) in Juniper Networks Junos OS allows a specific SNMP request to trigger an infinite loop causing a high CPU usage Denial of…

  • CVE-2014-5012MedJan 10, 2020
    risk 0.42cvss 6.5epss 0.01

    DOMPDF before 0.6.2 allows denial of service.

  • CVE-2019-20201MedDec 31, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.

  • CVE-2019-15584MedDec 20, 2019
    risk 0.42cvss 6.5epss 0.01

    A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

  • CVE-2019-12420HigDec 12, 2019
    risk 0.42cvss 7.5epss 0.07

    In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.

  • CVE-2019-16671MedDec 6, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a device with a special packet because of Uncontrolled Resource Consumption.

  • CVE-2019-15593MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.02

    GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.

  • CVE-2019-10504MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    Firmware not able to send EXT scan response to host within 1 sec due to resource consumption issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MSM8909W, Qualcomm 215, SD…

  • CVE-2011-1459MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.01

    The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin.

  • CVE-2019-7620HigOct 30, 2019
    risk 0.42cvss 7.5epss 0.02

    Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop…

  • CVE-2019-15264MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a…

  • CVE-2019-17592HigOct 14, 2019
    risk 0.42cvss 7.5epss 0.02

    The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.

  • CVE-2019-12714MedOct 2, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software improperly…

  • CVE-2019-12700MedOct 2, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of…

  • CVE-2019-9349MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…