VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,161)

page 108 of 209
  • CVE-2021-3690HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

  • CVE-2021-3670MedAug 23, 2022
    risk 0.42cvss 6.5epss 0.02

    MaxQueryDuration not honoured in Samba AD DC LDAP

  • CVE-2021-20298HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.

  • CVE-2022-25304HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.01

    All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by…

  • CVE-2022-21208HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.01

    The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of…

  • CVE-2022-35013MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp.

  • CVE-2022-35241MedAug 4, 2022
    risk 0.42cvss 6.5epss 0.01

    In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2022-35923HigAug 2, 2022
    risk 0.42cvss 7.5epss 0.02

    v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service attack. In testing of the `lowercase()` function a payload…

  • CVE-2022-35922HigAug 1, 2022
    risk 0.42cvss 7.5epss 0.02

    Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would…

  • CVE-2022-31173HigAug 1, 2022
    risk 0.42cvss 7.5epss 0.02

    Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. Users are advised to upgrade. Users unable to upgrade should limit the recursion…

  • CVE-2022-25891HigJul 15, 2022
    risk 0.42cvss 7.5epss 0.02

    The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.

  • CVE-2022-31781HigJul 13, 2022
    risk 0.42cvss 7.5epss 0.02

    Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause catastrophic backtracking, taking exponential time to complete. Specifically, this is about the…

  • CVE-2022-31129HigJul 6, 2022
    risk 0.42cvss 7.5epss 0.06

    moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried…

  • CVE-2022-31016MedJun 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial of Service. The attacker must…

  • CVE-2022-31054HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.02

    Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. `ioutil.ReadAll()` reads all the data into memory. As such, an attacker who sends a large request…

  • CVE-2022-1708HigJun 7, 2022
    risk 0.42cvss 7.5epss 0.03

    A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and…

  • CVE-2022-31018HigJun 2, 2022
    risk 0.42cvss 7.5epss 0.02

    Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` method on a JSON…

  • CVE-2022-27781HigJun 2, 2022
    risk 0.42cvss 7.5epss 0.03

    libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to…

  • CVE-2022-27640MedMay 20, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affected devices improperly handles excessive ARP broadcast requests. This could allow an attacker to create a denial of service condition by…

  • CVE-2022-23267HigMay 10, 2022
    risk 0.42cvss 7.5epss 0.06

    .NET and Visual Studio Denial of Service Vulnerability