VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 183 of 191
  • CVE-2022-47934MedDec 24, 2022
    risk 0.00cvss 6.5epss 0.01

    Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This is caused by an incomplete fix for CVE-2022-47932 and CVE-2022-47934.

  • CVE-2022-47932MedDec 24, 2022
    risk 0.00cvss 6.5epss 0.01

    Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This vulnerability is caused by an incomplete fix for CVE-2022-47933.

  • CVE-2022-41969LowDec 1, 2022
    risk 0.00cvss 2.4epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11,…

  • CVE-2022-41968LowDec 1, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5…

  • CVE-2022-39346LowNov 25, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud…

  • CVE-2022-45873MedNov 23, 2022
    risk 0.00cvss 5.5epss 0.00

    systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put…

  • CVE-2022-4006LowNov 15, 2022
    risk 0.00cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to…

  • CVE-2022-39330MedOct 27, 2022
    risk 0.00cvss 4.8epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing…

  • CVE-2022-23951MedSep 21, 2022
    risk 0.00cvss 5.5epss 0.00

    In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.

  • CVE-2022-39209HigSep 15, 2022
    risk 0.00cvss 7.5epss 0.02

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.…

  • CVE-2022-2962HigSep 13, 2022
    risk 0.00cvss 7.8epss 0.00

    A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO address. This can cause the device to trigger MMIO handlers…

  • CVE-2022-36064MedSep 6, 2022
    risk 0.00cvss 5.9epss 0.01

    Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shells `Bash` and `Dash`, or any not-officially-supported Unix shell; and/or using the `escape` or…

  • CVE-2020-29260HigSep 2, 2022
    risk 0.00cvss 7.5epss 0.01

    libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

  • CVE-2020-35534MedSep 1, 2022
    risk 0.00cvss 5.5epss 0.00

    In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.

  • CVE-2022-1325MedAug 31, 2022
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from disk or from a virtual…

  • CVE-2022-0669MedAug 29, 2022
    risk 0.00cvss 6.5epss 0.00

    A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages…

  • CVE-2021-3764MedAug 23, 2022
    risk 0.00cvss 5.5epss 0.00

    A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availability.

  • CVE-2021-3670MedAug 23, 2022
    risk 0.00cvss 6.5epss 0.02

    MaxQueryDuration not honoured in Samba AD DC LDAP

  • CVE-2022-25888HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.01

    The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge…

  • CVE-2022-2053HigAug 5, 2022
    risk 0.00cvss 7.5epss 0.01

    When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/proxy. This behavior results in that a front-end proxy marking…