VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,161)

page 130 of 209
  • CVE-2025-25208MedJun 9, 2025
    risk 0.37cvss 5.7epss 0.00

    A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

  • CVE-2025-25207MedJun 9, 2025
    risk 0.37cvss 5.7epss 0.00

    The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an…

  • CVE-2025-2811MedApr 26, 2025
    risk 0.37cvss 5.7epss 0.00

    A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango,…

  • CVE-2024-34035MedFeb 25, 2025
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a significant quantity of E2 Subscription Requests originating from an xApp.

  • CVE-2024-28122MedMar 9, 2024
    risk 0.37cvss 6.8epss 0.01

    JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an…

  • CVE-2023-50121MedJan 6, 2024
    risk 0.37cvss 5.7epss 0.00

    Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).

  • CVE-2023-37263MedSep 15, 2023
    risk 0.37cvss 6.8epss 0.01

    Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows a field they don't have permission to see, the field will…

  • CVE-2023-1206MedJun 30, 2023
    risk 0.37cvss 5.7epss 0.01

    A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that…

  • CVE-2021-29453MedApr 19, 2021
    risk 0.37cvss 5.7epss 0.01

    matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle malicious images which are crafted to be small in file size, but large in complexity. A malicious user could upload a relatively…

  • CVE-2018-0029MedJul 11, 2018
    risk 0.37cvss 5.7epss 0.01

    While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore). This issue only affects Junos OS 15.1 and later releases, and affects both single core and…

  • CVE-2026-82001MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of…

  • CVE-2026-28617MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28596MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-16952MedAug 20, 2026
    risk 0.36cvss 5.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption.

  • CVE-2026-64724MedJul 27, 2026
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be…

  • CVE-2026-47044MedJul 21, 2026
    risk 0.36cvss 5.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes…

  • CVE-2026-45822MedJun 30, 2026
    risk 0.36cvss —epss 0.01

    decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and…

  • CVE-2026-28575MedJun 17, 2026
    risk 0.36cvss 5.5epss 0.00

    In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution…

  • CVE-2026-0064MedJun 17, 2026
    risk 0.36cvss 5.5epss 0.00

    In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0074MedJun 1, 2026
    risk 0.36cvss 5.5epss 0.00

    In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.