CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,838)
page 122 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21280 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-38210 | Med | 0.36 | 5.5 | 0.00 | Aug 10, 2023 | Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires… | ||
| CVE-2023-37143 | Med | 0.36 | 5.5 | 0.01 | Jul 18, 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp(). | ||
| CVE-2023-37142 | Med | 0.36 | 5.5 | 0.01 | Jul 18, 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). | ||
| CVE-2023-37141 | Med | 0.36 | 5.5 | 0.01 | Jul 18, 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). | ||
| CVE-2023-37140 | Med | 0.36 | 5.5 | 0.01 | Jul 18, 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). | ||
| CVE-2023-21240 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-29767 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2023 | An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files. | ||
| CVE-2022-33303 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue. | ||
| CVE-2023-29735 | Med | 0.36 | 5.5 | 0.00 | May 30, 2023 | An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files. | ||
| CVE-2023-1981 | Med | 0.36 | 5.5 | 0.00 | May 26, 2023 | A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. | ||
| CVE-2023-20930 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-4008 | Med | 0.36 | 5.5 | 0.00 | May 10, 2023 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | ||
| CVE-2023-22874 | Med | 0.36 | 5.5 | 0.00 | May 5, 2023 | IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216. | ||
| CVE-2023-30408 | Med | 0.36 | 5.5 | 0.00 | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry. | ||
| CVE-2023-30406 | Med | 0.36 | 5.5 | 0.00 | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c. | ||
| CVE-2023-27652 | Med | 0.36 | 5.5 | 0.00 | Apr 20, 2023 | An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file. | ||
| CVE-2023-21033 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20910 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-24862 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2023 | Windows Secure Channel Denial of Service Vulnerability |
- risk 0.36cvss 5.5epss 0.00
In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
Adobe XMP Toolkit versions 2022.06 is affected by a Uncontrolled Resource Consumption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires…
- risk 0.36cvss 5.5epss 0.01
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp().
- risk 0.36cvss 5.5epss 0.01
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().
- risk 0.36cvss 5.5epss 0.01
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray().
- risk 0.36cvss 5.5epss 0.01
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount().
- risk 0.36cvss 5.5epss 0.00
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.
- risk 0.36cvss 5.5epss 0.00
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.
- risk 0.36cvss 5.5epss 0.00
An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.
- risk 0.36cvss 5.5epss 0.00
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
- risk 0.36cvss 5.5epss 0.00
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
- risk 0.36cvss 5.5epss 0.00
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.
- risk 0.36cvss 5.5epss 0.00
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.
- risk 0.36cvss 5.5epss 0.00
Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.
- risk 0.36cvss 5.5epss 0.00
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.
- risk 0.36cvss 5.5epss 0.00
In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.01
Windows Secure Channel Denial of Service Vulnerability