VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 184 of 191
  • CVE-2022-25852HigJun 17, 2022
    risk 0.00cvss 7.5epss 0.01

    All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's…

  • CVE-2022-29225HigJun 9, 2022
    risk 0.00cvss 7.5epss 0.02

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small…

  • CVE-2022-31028HigJun 7, 2022
    risk 0.00cvss 7.5epss 0.03

    MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing…

  • CVE-2022-1982MedJun 2, 2022
    risk 0.00cvss 4.3epss 0.01

    Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

  • CVE-2022-29243MedMay 31, 2022
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app passwords with long names. These long names are then loaded into…

  • CVE-2022-1699HigMay 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

  • CVE-2022-24726HigMar 10, 2022
    risk 0.00cvss 7.5epss 0.02

    Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane…

  • CVE-2021-3733MedMar 10, 2022
    risk 0.00cvss 6.5epss 0.05

    There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially…

  • CVE-2022-24741LowMar 9, 2022
    risk 0.00cvss 3.5epss 0.02

    Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud…

  • CVE-2022-0695MedFeb 24, 2022
    risk 0.00cvss 5.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0476MedFeb 23, 2022
    risk 0.00cvss 5.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-21698HigFeb 15, 2022
    risk 0.00cvss 7.5epss 0.06

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through…

  • CVE-2022-21721MedJan 28, 2022
    risk 0.00cvss 5.9epss 0.02

    Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial of service attack for anyone using i18n functionality. In order to be affected by this CVE, one must use next start or a custom…

  • CVE-2022-21653MedJan 5, 2022
    risk 0.00cvss 5.9epss 0.01

    Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not…

  • CVE-2021-3622MedDec 23, 2021
    risk 0.00cvss 4.3epss 0.05

    A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to…

  • CVE-2021-41168MedOct 21, 2021
    risk 0.00cvss 6.5epss 0.01

    Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was found to be vulnerable to denial of service attacks to its reference table implementation. References written in markdown `…

  • CVE-2021-33609MedOct 13, 2021
    risk 0.00cvss 4.3epss 0.01

    Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.

  • CVE-2021-41115MedOct 7, 2021
    risk 0.00cvss 4.3epss 0.02

    Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via arbitrary regular expressions. Malicious organization…

  • CVE-2021-41118MedOct 4, 2021
    risk 0.00cvss 5.3epss 0.01

    The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. In affected versions unsanitised input of regular expression date within the parameters of the DPL parser function, allowed for the…

  • CVE-2021-32832MedAug 30, 2021
    risk 0.00cvss 4.3epss 0.02

    Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3,…