VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,838)

page 121 of 192
  • CVE-2023-31889MedApr 29, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service via crafted GET request.

  • CVE-2024-33259MedApr 26, 2024
    risk 0.36cvss 5.5epss 0.00

    Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanner-util.c.

  • CVE-2021-46939MedFeb 27, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: tracing: Restructure trace_clock_global() to never block It was reported that a fix to the ring buffer recursion detection would cause a hung machine when performing suspend / resume testing. The following…

  • CVE-2023-25769MedFeb 14, 2024
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-25452MedFeb 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

  • CVE-2023-45028MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.00

    An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. We have already fixed the…

  • CVE-2023-6450MedJan 19, 2024
    risk 0.36cvss 5.5epss 0.00

    An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service.

  • CVE-2023-49557MedJan 3, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.

  • CVE-2023-49555MedJan 3, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.

  • CVE-2023-47025MedNov 16, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.

  • CVE-2023-25949MedNov 14, 2023
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-43786MedOct 10, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.

  • CVE-2023-21253MedOct 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2020-24089MedSep 20, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DoS).

  • CVE-2023-32665MedSep 14, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.

  • CVE-2023-32611MedSep 14, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

  • CVE-2023-29499MedSep 14, 2023
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.

  • CVE-2023-24620MedAug 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is…

  • CVE-2022-48063MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.

  • CVE-2020-18770MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.