CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,161)
page 137 of 209| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-47355 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In log service, there is a missing permission check. This could lead to local denial of service in log service. | ||
| CVE-2022-47354 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In log service, there is a missing permission check. This could lead to local denial of service in log service. | ||
| CVE-2022-38674 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. | ||
| CVE-2023-20922 | Med | 0.36 | 5.5 | 0.00 | Jan 26, 2023 | In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20908 | Med | 0.36 | 5.5 | 0.00 | Jan 26, 2023 | In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-46351 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2022 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All… | ||
| CVE-2022-20482 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2022 | In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not… | ||
| CVE-2022-39128 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-39127 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-39126 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-39125 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-39124 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-39123 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | ||
| CVE-2022-38687 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed. | ||
| CVE-2022-38679 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed. | ||
| CVE-2022-38677 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2022 | In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed. | ||
| CVE-2022-20425 | Med | 0.36 | 5.5 | 0.00 | Oct 11, 2022 | In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2020-35534 | Med | 0.36 | 5.5 | 0.00 | Sep 1, 2022 | In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files. | ||
| CVE-2021-3669 | Med | 0.36 | 5.5 | 0.00 | Aug 26, 2022 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | ||
| CVE-2021-4022 | Med | 0.36 | 5.5 | 0.00 | Aug 25, 2022 | A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the build) memory address. |
- risk 0.36cvss 5.5epss 0.00
In log service, there is a missing permission check. This could lead to local denial of service in log service.
- risk 0.36cvss 5.5epss 0.00
In log service, there is a missing permission check. This could lead to local denial of service in log service.
- risk 0.36cvss 5.5epss 0.00
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
- risk 0.36cvss 5.5epss 0.00
In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…
- risk 0.36cvss 5.5epss 0.00
In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- risk 0.36cvss 5.5epss 0.00
In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
- risk 0.36cvss 5.5epss 0.00
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
- risk 0.36cvss 5.5epss 0.00
A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the build) memory address.