VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,161)

page 119 of 209
  • CVE-2018-15852MedAug 25, 2018
    risk 0.42cvss 6.5epss 0.01

    Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or…

  • CVE-2018-15671MedAug 21, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.

  • CVE-2018-15470MedAug 17, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making up a tuple. As indicated in section 7.7.3 "Operations on data structures" of the OCaml manual, the order of evaluation of…

  • CVE-2018-15469MedAug 17, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be properly set up, resulting in subsequent grant-related…

  • CVE-2018-13863HigJul 10, 2018
    risk 0.42cvss 7.5epss 0.02

    The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Service (ReDoS) in lib/bson/decimal128.js. The flaw is triggered when the Decimal128.fromString() function is called to parse a long…

  • CVE-2016-10724HigJul 5, 2018
    risk 0.42cvss 7.5epss 0.02

    Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized…

  • CVE-2018-13251MedJul 5, 2018
    risk 0.42cvss 6.5epss 0.01

    In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, related to parseSWF_DEFINEBITSJPEG2. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

  • CVE-2018-3711HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.

  • CVE-2017-16138HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

  • CVE-2017-16136HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.01

    method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is…

  • CVE-2017-16098HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact…

  • CVE-2017-16021MedJun 4, 2018
    risk 0.42cvss 6.5epss 0.01

    uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do this, uri-js uses a regular expression, This regular expression is vulnerable to redos. This causes the program to hang and the CPU…

  • CVE-2016-10523HigMay 31, 2018
    risk 0.42cvss 7.5epss 0.02

    MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very little bandwidth.

  • CVE-2015-9242HigMay 29, 2018
    risk 0.42cvss 7.5epss 0.02

    Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.

  • CVE-2015-9241HigMay 29, 2018
    risk 0.42cvss 7.5epss 0.02

    Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 error back to the sender, hapi node module before 11.1.3 will continue to hold the socket open until timed out (default…

  • CVE-2018-0285MedMay 2, 2018
    risk 0.42cvss 6.5epss 0.03

    A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interface. The vulnerability is due to exhaustion of disk space. An attacker could exploit this vulnerability by performing certain…

  • CVE-2018-1277MedApr 30, 2018
    risk 0.42cvss 6.5epss 0.01

    Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially…

  • CVE-2018-8777HigApr 3, 2018
    risk 0.42cvss 7.5epss 0.04

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of service (memory consumption).

  • CVE-2018-7876MedMar 8, 2018
    risk 0.42cvss 6.5epss 0.02

    In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service via a crafted file.

  • CVE-2017-18214HigMar 4, 2018
    risk 0.42cvss 7.5epss 0.04

    The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.