VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,814)

page 155 of 191
  • CVE-2023-29046MedNov 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an…

  • CVE-2023-5349MedOct 30, 2023
    risk 0.28cvss 5.3epss 0.01

    A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.

  • CVE-2023-5522MedOct 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

  • CVE-2023-5333MedOct 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

  • CVE-2023-5330MedOct 9, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.

  • CVE-2023-26151MedOct 3, 2023
    risk 0.28cvss 5.3epss 0.01

    Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

  • CVE-2023-26144MedSep 20, 2023
    risk 0.28cvss 5.3epss 0.01

    Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system…

  • CVE-2023-3637MedJul 25, 2023
    risk 0.28cvss 4.3epss 0.01

    An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to…

  • CVE-2023-3614MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.

  • CVE-2023-3593MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.

  • CVE-2023-3585MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.

  • CVE-2023-26434MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…

  • CVE-2023-26433MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…

  • CVE-2023-26432MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…

  • CVE-2023-2831MedJun 16, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.

  • CVE-2023-2785MedJun 16, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service

  • CVE-2023-33958MedJun 6, 2023
    risk 0.28cvss 5.4epss 0.00

    notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation verify command on the…

  • CVE-2023-26044MedMay 17, 2023
    risk 0.28cvss 5.3epss 0.01

    react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerability that can cause high CPU load when processing large HTTP request bodies. This vulnerability…

  • CVE-2023-26048MedApr 18, 2023
    risk 0.28cvss 5.3epss 0.03

    Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.getParameter()` or `HttpServletRequest.getParts()` may cause `OutOfMemoryError` when the client sends…

  • CVE-2023-1787MedApr 5, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.