VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 168 of 206
  • CVE-2023-6193MedDec 12, 2023
    risk 0.28cvss 5.3epss 0.01

    quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by…

  • CVE-2023-49809MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoint and make it crash. After a few repetitions, the plugin is disabled. 

  • CVE-2023-45847MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to send a specially crafted request and crash the Playbooks plugin

  • CVE-2023-49290MedDec 5, 2023
    risk 0.28cvss 5.3epss 0.01

    lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p2c parameter set too high in JWE's algorithm PBES2-* could lead to a denial of service. The JWE key management algorithms based on PBKDF2 require a JOSE Header…

  • CVE-2023-48369MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

  • CVE-2023-48268MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).

  • CVE-2023-40703MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 

  • CVE-2023-29046MedNov 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an…

  • CVE-2023-5349MedOct 30, 2023
    risk 0.28cvss 5.3epss 0.01

    A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.

  • CVE-2023-5522MedOct 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

  • CVE-2023-5333MedOct 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

  • CVE-2023-5330MedOct 9, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.

  • CVE-2023-26151MedOct 3, 2023
    risk 0.28cvss 5.3epss 0.01

    Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

  • CVE-2023-26144MedSep 20, 2023
    risk 0.28cvss 5.3epss 0.01

    Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system…

  • CVE-2023-3637MedJul 25, 2023
    risk 0.28cvss 4.3epss 0.01

    An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to…

  • CVE-2023-3614MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.

  • CVE-2023-3593MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.

  • CVE-2023-3585MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.

  • CVE-2023-26434MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…

  • CVE-2023-26433MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…