VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,161)

page 138 of 209
  • CVE-2021-3764MedAug 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availability.

  • CVE-2021-3759MedAug 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The…

  • CVE-2022-28191MedMay 17, 2022
    risk 0.36cvss 5.5epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.

  • CVE-2022-25169MedMay 16, 2022
    risk 0.36cvss 5.5epss 0.02

    The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

  • CVE-2021-33135MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-4115MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.01

    There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and…

  • CVE-2021-46668MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

  • CVE-2021-33073MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access.

  • CVE-2020-21573MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.

  • CVE-2021-35559MedOct 20, 2021
    risk 0.36cvss 5.3epss 0.16

    Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability…

  • CVE-2021-3679MedAug 5, 2021
    risk 0.36cvss 5.5epss 0.01

    A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources…

  • CVE-2021-25701MedJul 21, 2021
    risk 0.36cvss 5.5epss 0.00

    The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs, which allowed an attacker to cause a denial of service.

  • CVE-2021-32014MedJul 19, 2021
    risk 0.36cvss 5.5epss 0.01

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.

  • CVE-2021-32013MedJul 19, 2021
    risk 0.36cvss 5.5epss 0.01

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).

  • CVE-2021-32012MedJul 19, 2021
    risk 0.36cvss 5.5epss 0.01

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).

  • CVE-2020-12296MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-12291MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-26945MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

  • CVE-2021-26260MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

  • CVE-2021-23215MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.