VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 182 of 191
  • CVE-2022-37050MedAug 22, 2023
    risk 0.00cvss 6.5epss 0.01

    In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the…

  • CVE-2023-34872MedJul 31, 2023
    risk 0.00cvss 5.5epss 0.01

    A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

  • CVE-2023-38498MedJul 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite…

  • CVE-2022-4952LowJul 17, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The…

  • CVE-2023-36818MedJul 14, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this…

  • CVE-2023-3108MedJul 11, 2023
    risk 0.00cvss 6.2epss 0.00

    A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.

  • CVE-2023-3398HigJun 26, 2023
    risk 0.00cvss 7.5epss 0.01

    Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.

  • CVE-2023-34109MedJun 7, 2023
    risk 0.00cvss 6.5epss 0.01

    zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which are using the second argument of the zxcvbn function. It can result in an unbounded resource consumption as the user inputs array…

  • CVE-2023-33297HigMay 22, 2023
    risk 0.00cvss 7.5epss 0.01

    Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.

  • CVE-2023-27734MedApr 4, 2023
    risk 0.00cvss 5.5epss 0.00

    An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.

  • CVE-2023-26485MedMar 31, 2023
    risk 0.00cvss 5.3epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing…

  • CVE-2023-24824MedMar 31, 2023
    risk 0.00cvss 5.3epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing…

  • CVE-2023-28644MedMar 30, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the…

  • CVE-2023-1654HigMar 27, 2023
    risk 0.00cvss 7.8epss 0.00

    Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.

  • CVE-2023-1605HigMar 23, 2023
    risk 0.00cvss 7.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

  • CVE-2023-27567HigMar 3, 2023
    risk 0.00cvss 7.5epss 0.01

    In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.

  • CVE-2023-25816MedFeb 25, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in…

  • CVE-2023-23616LowJan 28, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the request. This could…

  • CVE-2022-41861MedJan 17, 2023
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.

  • CVE-2023-22470LowJan 14, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is…