VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,838)

page 122 of 192
  • CVE-2023-21280MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-38210MedAug 10, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires…

  • CVE-2023-37143MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.01

    ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp().

  • CVE-2023-37142MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.01

    ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().

  • CVE-2023-37141MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.01

    ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray().

  • CVE-2023-37140MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.01

    ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount().

  • CVE-2023-21240MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-29767MedJun 9, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.

  • CVE-2022-33303MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.

  • CVE-2023-29735MedMay 30, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.

  • CVE-2023-1981MedMay 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.

  • CVE-2023-20930MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-4008MedMay 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

  • CVE-2023-22874MedMay 5, 2023
    risk 0.36cvss 5.5epss 0.00

    IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.

  • CVE-2023-30408MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.

  • CVE-2023-30406MedApr 24, 2023
    risk 0.36cvss 5.5epss 0.00

    Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.

  • CVE-2023-27652MedApr 20, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.

  • CVE-2023-21033MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.00

    In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20910MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.00

    In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-24862MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Secure Channel Denial of Service Vulnerability