VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 181 of 191
  • CVE-2024-27100MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead to excessive resource…

  • CVE-2024-27085MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version of Discourse. Users are…

  • CVE-2024-24827MedMar 15, 2024
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process. Do note that the impact…

  • CVE-2024-27088NonFeb 26, 2024
    risk 0.00cvss 0.0epss 0.01

    es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.

  • CVE-2024-23835HigFeb 26, 2024
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround,…

  • CVE-2024-24814HigFeb 13, 2024
    risk 0.00cvss 7.5epss 0.01

    mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes…

  • CVE-2024-23323MedFeb 9, 2024
    risk 0.00cvss 4.3epss 0.01

    Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1,…

  • CVE-2024-24575HigFeb 6, 2024
    risk 0.00cvss 7.5epss 0.01

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop,…

  • CVE-2023-52425HigFeb 4, 2024
    risk 0.00cvss 7.5epss 0.02

    libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.

  • CVE-2024-23824MedFeb 2, 2024
    risk 0.00cvss 4.7epss 0.01

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is…

  • CVE-2023-50020HigJan 2, 2024
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

  • CVE-2023-50019MedJan 2, 2024
    risk 0.00cvss 5.9epss 0.01

    An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.

  • CVE-2023-26157MedJan 2, 2024
    risk 0.00cvss 5.5epss 0.01

    Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

  • CVE-2023-41102HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version…

  • CVE-2023-42813MedNov 13, 2023
    risk 0.00cvss 6.1epss 0.01

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno…

  • CVE-2023-45150MedOct 16, 2023
    risk 0.00cvss 4.3epss 0.00

    Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It…

  • CVE-2023-5595MedOct 16, 2023
    risk 0.00cvss 5.5epss 0.00

    Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.

  • CVE-2023-3153MedOct 4, 2023
    risk 0.00cvss 5.3epss 0.01

    A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.

  • CVE-2023-43771MedSep 22, 2023
    risk 0.00cvss 5.5epss 0.00

    In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.

  • CVE-2022-48571HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.