VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,812)

page 157 of 191
  • CVE-2021-37865MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

  • CVE-2022-21670MedJan 10, 2022
    risk 0.28cvss 5.3epss 0.02

    markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.

  • CVE-2021-43843MedDec 20, 2021
    risk 0.28cvss 5.3epss 0.02

    jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient tfor protection from a Regular Expression Denial of Service (ReDoS) attack. If an attacker can put a lot…

  • CVE-2021-43838MedDec 17, 2021
    risk 0.28cvss 5.3epss 0.01

    jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users are vulnerable to a regular expression denial-of-service (ReDoS) attack. If attacker can put a lot of JSX elements into `` tag, an internal…

  • CVE-2021-41229MedNov 12, 2021
    risk 0.28cvss 4.3epss 0.01

    BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can…

  • CVE-2021-39171MedAug 27, 2021
    risk 0.28cvss 5.3epss 0.01

    Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduced or denied service.…

  • CVE-2021-23392MedJun 8, 2021
    risk 0.28cvss 5.3epss 0.02

    The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.

  • CVE-2020-28469MedJun 3, 2021
    risk 0.28cvss 5.3epss 0.05

    This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.

  • CVE-2021-32657MedJun 1, 2021
    risk 0.28cvss 4.3epss 0.02

    Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20.0.10, and 21.0.2, a malicious user may be able to break the user administration page. This would disallow administrators to administrate users on the Nextcloud…

  • CVE-2021-32640MedMay 25, 2021
    risk 0.28cvss 5.3epss 0.03

    ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in [email protected] (https://github.com/websockets/ws/commit/00c425e…

  • CVE-2021-21419MedMay 7, 2021
    risk 0.28cvss 5.3epss 0.02

    Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts…

  • CVE-2021-23343MedMay 4, 2021
    risk 0.28cvss 5.3epss 0.02

    All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

  • CVE-2021-23364MedApr 28, 2021
    risk 0.28cvss 5.3epss 0.02

    The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

  • CVE-2021-23382MedApr 26, 2021
    risk 0.28cvss 5.3epss 0.03

    The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).

  • CVE-2021-29469MedApr 23, 2021
    risk 0.28cvss 5.3epss 0.02

    Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service. The issue is patched in version…

  • CVE-2021-23368MedApr 12, 2021
    risk 0.28cvss 5.3epss 0.04

    The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

  • CVE-2021-22177MedApr 1, 2021
    risk 0.28cvss 4.3epss 0.01

    Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

  • CVE-2018-1109MedMar 30, 2021
    risk 0.28cvss 5.3epss 0.01

    A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.

  • CVE-2018-1107MedMar 30, 2021
    risk 0.28cvss 5.3epss 0.01

    It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.

  • CVE-2021-23362MedMar 23, 2021
    risk 0.28cvss 5.3epss 0.04

    The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.