CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (3,811)
page 181 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27100 | Med | 0.00 | 6.5 | 0.01 | Mar 15, 2024 | Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead to excessive resource… | ||
| CVE-2024-27085 | Med | 0.00 | 6.5 | 0.01 | Mar 15, 2024 | Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version of Discourse. Users are… | ||
| CVE-2024-24827 | Med | 0.00 | 5.3 | 0.01 | Mar 15, 2024 | Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process. Do note that the impact… | ||
| CVE-2024-27088 | Non | 0.00 | 0.0 | 0.01 | Feb 26, 2024 | es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63. | ||
| CVE-2024-23835 | Hig | 0.00 | 7.5 | 0.01 | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround,… | ||
| CVE-2024-24814 | Hig | 0.00 | 7.5 | 0.01 | Feb 13, 2024 | mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes… | ||
| CVE-2024-23323 | Med | 0.00 | 4.3 | 0.01 | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1,… | ||
| CVE-2024-24575 | Hig | 0.00 | 7.5 | 0.01 | Feb 6, 2024 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop,… | ||
| CVE-2023-52425 | Hig | 0.00 | 7.5 | 0.02 | Feb 4, 2024 | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. | ||
| CVE-2024-23824 | Med | 0.00 | 4.7 | 0.01 | Feb 2, 2024 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is… | ||
| CVE-2023-50020 | Hig | 0.00 | 7.5 | 0.01 | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF. | ||
| CVE-2023-50019 | Med | 0.00 | 5.9 | 0.01 | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response. | ||
| CVE-2023-26157 | Med | 0.00 | 5.5 | 0.01 | Jan 2, 2024 | Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c. | ||
| CVE-2023-41102 | Hig | 0.00 | 7.5 | 0.01 | Nov 17, 2023 | An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version… | ||
| CVE-2023-42813 | Med | 0.00 | 6.1 | 0.01 | Nov 13, 2023 | Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno… | ||
| CVE-2023-45150 | Med | 0.00 | 4.3 | 0.00 | Oct 16, 2023 | Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It… | ||
| CVE-2023-5595 | Med | 0.00 | 5.5 | 0.00 | Oct 16, 2023 | Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV. | ||
| CVE-2023-3153 | Med | 0.00 | 5.3 | 0.01 | Oct 4, 2023 | A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured. | ||
| CVE-2023-43771 | Med | 0.00 | 5.5 | 0.00 | Sep 22, 2023 | In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program. | ||
| CVE-2022-48571 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP. |
- risk 0.00cvss 6.5epss 0.01
Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead to excessive resource…
- risk 0.00cvss 6.5epss 0.01
Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version of Discourse. Users are…
- risk 0.00cvss 5.3epss 0.01
Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process. Do note that the impact…
- risk 0.00cvss 0.0epss 0.01
es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.
- risk 0.00cvss 7.5epss 0.01
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround,…
- risk 0.00cvss 7.5epss 0.01
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes…
- risk 0.00cvss 4.3epss 0.01
Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1,…
- risk 0.00cvss 7.5epss 0.01
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop,…
- risk 0.00cvss 7.5epss 0.02
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
- risk 0.00cvss 4.7epss 0.01
mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is…
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
- risk 0.00cvss 5.9epss 0.01
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
- risk 0.00cvss 5.5epss 0.01
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version…
- risk 0.00cvss 6.1epss 0.01
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno…
- risk 0.00cvss 4.3epss 0.00
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It…
- risk 0.00cvss 5.5epss 0.00
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
- risk 0.00cvss 5.3epss 0.01
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.
- risk 0.00cvss 5.5epss 0.00
In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.
- risk 0.00cvss 7.5epss 0.01
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.