VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,148)

page 114 of 208
  • CVE-2020-36066HigJan 5, 2021
    risk 0.42cvss 7.5epss 0.02

    GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.

  • CVE-2020-7771HigJan 4, 2021
    risk 0.42cvss 7.5epss 0.02

    The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.

  • CVE-2020-35857HigDec 31, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption.

  • CVE-2020-26289HigDec 28, 2020
    risk 0.42cvss 7.5epss 0.02

    date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

  • CVE-2020-27722MedDec 24, 2020
    risk 0.42cvss 6.5epss 0.01

    In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption.

  • CVE-2020-27724MedDec 24, 2020
    risk 0.42cvss 6.5epss 0.01

    In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending specially-crafted…

  • CVE-2020-5682HigDec 16, 2020
    risk 0.42cvss 7.5epss 0.02

    Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier…

  • CVE-2020-35380HigDec 15, 2020
    risk 0.42cvss 7.5epss 0.01

    GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.

  • CVE-2020-7791HigDec 11, 2020
    risk 0.42cvss 7.5epss 0.03

    This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.

  • CVE-2020-7793HigDec 11, 2020
    risk 0.42cvss 7.5epss 0.04

    The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

  • CVE-2020-27813HigDec 2, 2020
    risk 0.42cvss 7.5epss 0.02

    An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

  • CVE-2020-7754HigOct 27, 2020
    risk 0.42cvss 7.5epss 0.03

    This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

  • CVE-2020-1689MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in a Virtual Chassis configuration, receipt of a stream of specific layer 2 frames can cause high CPU load, which could lead to traffic interruption. This issue does not occur when the device is…

  • CVE-2020-1687MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in (Ethernet VPN) EVPN-(Virtual Extensible LAN) VXLAN configuration, receipt of a stream of specific VXLAN encapsulated layer 2 frames can cause high CPU load, which could lead to network protocol…

  • CVE-2020-1678MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.00

    On Juniper Networks Junos OS and Junos OS Evolved platforms with EVPN configured, receipt of specific BGP packets causes a slow memory leak. If the memory is exhausted the rpd process might crash. If the issue occurs, the memory leak could be seen by executing the "show task…

  • CVE-2020-1670MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX4300 Series, receipt of a stream of specific IPv4 packets can cause Routing Engine (RE) high CPU load, which could lead to network protocol operation issue and traffic interruption. This specific packets can originate only from within the broadcast domain…

  • CVE-2020-1668MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks EX2300 Series, receipt of a stream of specific multicast packets by the layer2 interface can cause high CPU load, which could lead to traffic interruption. This issue occurs when multicast packets are received by the layer 2 interface. To check if the device…

  • CVE-2020-11645MedOct 15, 2020
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to limit availability of GateManager instances.

  • CVE-2020-3543MedOct 8, 2020
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vulnerability is due to…

  • CVE-2019-20922HigSep 30, 2020
    risk 0.42cvss 7.5epss 0.04

    Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.