VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,838)

page 124 of 192
  • CVE-2022-20425MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-3669MedAug 26, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.

  • CVE-2021-4022MedAug 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the build) memory address.

  • CVE-2021-3759MedAug 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The…

  • CVE-2022-28191MedMay 17, 2022
    risk 0.36cvss 5.5epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.

  • CVE-2022-25169MedMay 16, 2022
    risk 0.36cvss 5.5epss 0.02

    The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

  • CVE-2021-33135MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-4115MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.01

    There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and…

  • CVE-2021-46668MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

  • CVE-2021-33073MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access.

  • CVE-2020-21573MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.

  • CVE-2021-35559MedOct 20, 2021
    risk 0.36cvss 5.3epss 0.16

    Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability…

  • CVE-2021-25701MedJul 21, 2021
    risk 0.36cvss 5.5epss 0.00

    The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs, which allowed an attacker to cause a denial of service.

  • CVE-2021-32014MedJul 19, 2021
    risk 0.36cvss 5.5epss 0.01

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.

  • CVE-2021-32013MedJul 19, 2021
    risk 0.36cvss 5.5epss 0.01

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).

  • CVE-2021-32012MedJul 19, 2021
    risk 0.36cvss 5.5epss 0.01

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).

  • CVE-2020-12296MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-12291MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-26945MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

  • CVE-2021-26260MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.