VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,161)

page 137 of 209
  • CVE-2022-47355MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In log service, there is a missing permission check. This could lead to local denial of service in log service.

  • CVE-2022-47354MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In log service, there is a missing permission check. This could lead to local denial of service in log service.

  • CVE-2022-38674MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

  • CVE-2023-20922MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20908MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-46351MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…

  • CVE-2022-20482MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not…

  • CVE-2022-39128MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39127MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39126MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39125MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39124MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-39123MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2022-38687MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed.

  • CVE-2022-38679MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed.

  • CVE-2022-38677MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.

  • CVE-2022-20425MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-35534MedSep 1, 2022
    risk 0.36cvss 5.5epss 0.00

    In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.

  • CVE-2021-3669MedAug 26, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.

  • CVE-2021-4022MedAug 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the build) memory address.