VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,161)

page 106 of 209
  • CVE-2023-22792HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.02

    A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination with a specially crafted X_FORWARDED_HOST header can cause the regular expression engine to enter a state of catastrophic backtracking.…

  • CVE-2022-44572HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.02

    A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in…

  • CVE-2022-44571HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.01

    There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of…

  • CVE-2022-44570HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.02

    A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any…

  • CVE-2022-44566HigFeb 9, 2023
    risk 0.42cvss 7.5epss 0.01

    A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer…

  • CVE-2022-40480MedFeb 8, 2023
    risk 0.42cvss 6.5epss 0.00

    Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.

  • CVE-2022-27507MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Authenticated denial of service

  • CVE-2023-20047MedJan 20, 2023
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to…

  • CVE-2022-34335MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.

  • CVE-2022-46740MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.00

    There is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a denial of service (DoS) condition.

  • CVE-2022-3064HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.02

    Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

  • CVE-2020-36568HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.02

    Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.

  • CVE-2019-25072HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.

  • CVE-2022-4767HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Denial of Service in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2021-35065HigDec 26, 2022
    risk 0.42cvss 7.5epss 0.02

    The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

  • CVE-2022-40899HigDec 23, 2022
    risk 0.42cvss 7.5epss 0.02

    An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

  • CVE-2022-42929MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird…

  • CVE-2022-3510HigDec 12, 2022
    risk 0.42cvss 7.5epss 0.01

    A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with…

  • CVE-2022-3509HigDec 12, 2022
    risk 0.42cvss 7.5epss 0.01

    A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or…

  • CVE-2022-23492HigDec 8, 2022
    risk 0.42cvss 7.5epss 0.01

    go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause…