VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 111 of 192
  • CVE-2025-0426MedFeb 13, 2025
    risk 0.40cvss 6.2epss 0.00

    A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

  • CVE-2024-8939MedSep 17, 2024
    risk 0.40cvss 6.2epss 0.00

    A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-based sentence or chat completion accepts a best_of parameter to return the best…

  • CVE-2024-0115MedAug 12, 2024
    risk 0.40cvss 6.1epss 0.00

    NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vulnerability may lead to denial of service…

  • CVE-2024-5652MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode.

  • CVE-2021-47329MedMay 21, 2024
    risk 0.40cvss 6.2epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix resource leak in case of probe failure The driver doesn't clean up all the allocated resources properly when scsi_add_host(), megasas_start_aen() function fails during the PCI device…

  • CVE-2024-1014MedJan 29, 2024
    risk 0.40cvss 6.2epss 0.01

    Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets.

  • CVE-2023-36042MedNov 14, 2023
    risk 0.40cvss 6.2epss 0.01

    Visual Studio Denial of Service Vulnerability

  • CVE-2023-45167MedNov 10, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service. IBM X-Force ID: 267965.

  • CVE-2023-27484MedMar 9, 2023
    risk 0.40cvss 6.2epss 0.01

    crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. In affected versions an already highly privileged user able to create or update Compositions can specify an arbitrarily high index in a patch's `ToFieldPath`,…

  • CVE-2022-4816MedJan 23, 2023
    risk 0.40cvss 6.2epss 0.00

    A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.

  • CVE-2021-32821MedJan 3, 2023
    risk 0.40cvss 6.2epss 0.01

    MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at…

  • CVE-2022-39164MedDec 23, 2022
    risk 0.40cvss 6.2epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.

  • CVE-2022-39165MedDec 23, 2022
    risk 0.40cvss 6.2epss 0.00

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 235183.

  • CVE-2022-22101MedSep 2, 2022
    risk 0.40cvss 6.2epss 0.00

    Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto

  • CVE-2022-35776MedAug 9, 2022
    risk 0.40cvss 6.2epss 0.01

    Azure Site Recovery Denial of Service Vulnerability

  • CVE-2021-43933MedApr 20, 2022
    risk 0.40cvss 6.1epss 0.01

    The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources.

  • CVE-2020-3479MedSep 24, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service…

  • CVE-2018-16845MedNov 7, 2018
    risk 0.40cvss 6.1epss 0.10

    nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.…

  • CVE-2017-15529MedDec 13, 2017
    risk 0.40cvss 6.2epss 0.00

    Prior to 4.4.1.10, the Norton Family Android App can be susceptible to a Denial of Service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular device unavailable to its intended user by temporarily or indefinitely disrupting…

  • CVE-2016-9039MedJan 31, 2017
    risk 0.40cvss 6.2epss 0.01

    An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly…