VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,807)

page 180 of 191
  • CVE-2024-52520MedNov 15, 2024
    risk 0.00cvss 5.7epss 0.01

    Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10…

  • CVE-2024-7592HigAug 19, 2024
    risk 0.00cvss 7.5epss 0.02

    There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting…

  • CVE-2024-37299MedJul 30, 2024
    risk 0.00cvss 4.9epss 0.01

    Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

  • CVE-2024-38360MedJul 15, 2024
    risk 0.00cvss 4.9epss 0.00

    Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3…

  • CVE-2023-52340HigJul 5, 2024
    risk 0.00cvss 7.5epss 0.01

    The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket.

  • CVE-2024-5216HigJun 25, 2024
    risk 0.00cvss 7.5epss 0.01

    A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to create users with…

  • CVE-2023-45196HigJun 24, 2024
    risk 0.00cvss 7.5epss 0.01

    Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this…

  • CVE-2024-3153MedJun 6, 2024
    risk 0.00cvss 6.5epss 0.01

    mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. An attacker with the ability…

  • CVE-2024-4284MedMay 19, 2024
    risk 0.00cvss 4.9epss 0.01

    A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id…

  • CVE-2023-7258MedMay 15, 2024
    risk 0.00cvss 4.8epss 0.00

    A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past…

  • CVE-2024-32663HigMay 7, 2024
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 traffic can lead to Suricata using a large amount of memory. The issue has been addressed in Suricata 7.0.5…

  • CVE-2024-31994MedApr 19, 2024
    risk 0.00cvss 6.5epss 0.00

    Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. Mealie will attempt to retrieve this file in whole. If it can be retrieved, it may be stored on the file system in whole (leading to…

  • CVE-2024-31992MedApr 19, 2024
    risk 0.00cvss 6.5epss 0.01

    Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to a remote server, however these requests are not rate-limited. While there are efforts to prevent DDoS by implementing a…

  • CVE-2024-1569HigApr 16, 2024
    risk 0.00cvss 7.5epss 0.01

    parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of…

  • CVE-2024-3569HigApr 10, 2024
    risk 0.00cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [validatedRequest] middleware…

  • CVE-2021-47208MedApr 8, 2024
    risk 0.00cvss 4.3epss 0.01

    The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

  • CVE-2024-27100MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead to excessive resource…

  • CVE-2024-27085MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version of Discourse. Users are…

  • CVE-2024-24827MedMar 15, 2024
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process. Do note that the impact…

  • CVE-2024-27088NonFeb 26, 2024
    risk 0.00cvss 0.0epss 0.01

    es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.