VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 186 of 191
  • CVE-2021-26306HigJan 29, 2021
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() methods.

  • CVE-2020-28480HigJan 19, 2021
    risk 0.00cvss 7.3epss 0.01

    The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype…

  • CVE-2020-35875HigDec 31, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the tokio-rustls crate before 0.13.1 for Rust. Excessive memory usage may occur when data arrives quickly.

  • CVE-2020-29651HigDec 9, 2020
    risk 0.00cvss 7.5epss 0.05

    A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

  • CVE-2020-25201HigNov 4, 2020
    risk 0.00cvss 7.5epss 0.03

    HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.

  • CVE-2020-7755HigOct 27, 2020
    risk 0.00cvss 7.5epss 0.02

    All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.

  • CVE-2020-7753HigOct 27, 2020
    risk 0.00cvss 7.5epss 0.04

    All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

  • CVE-2020-26164MedOct 7, 2020
    risk 0.00cvss 5.5epss 0.01

    In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.

  • CVE-2020-15166HigSep 11, 2020
    risk 0.00cvss 7.5epss 0.03

    In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate…

  • CVE-2020-11080LowJun 3, 2020
    risk 0.00cvss 3.7epss 0.05

    In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again.…

  • CVE-2019-20812MedJun 3, 2020
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet.c can result in a denial of service (CPU consumption and soft lockup) in a certain failure case involving TPACKET_V3, aka CID-b43d1f9f7067.

  • CVE-2020-7218HigJan 31, 2020
    risk 0.00cvss 7.5epss 0.01

    HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.

  • CVE-2019-20176HigDec 31, 2019
    risk 0.00cvss 7.5epss 0.04

    In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.

  • CVE-2019-19922MedDec 22, 2019
    risk 0.00cvss 5.5epss 0.01

    kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1.…

  • CVE-2019-15538HigAug 25, 2019
    risk 0.00cvss 7.5epss 0.04

    An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails.…

  • CVE-2019-14262HigJul 25, 2019
    risk 0.00cvss 7.5epss 0.02

    MetadataExtractor 2.1.0 allows stack consumption.

  • CVE-2019-11470MedApr 23, 2019
    risk 0.00cvss 6.5epss 0.04

    The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for…

  • CVE-2018-16878MedApr 18, 2019
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS

  • CVE-2018-20030HigFeb 20, 2019
    risk 0.00cvss 7.5epss 0.04

    An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.

  • CVE-2019-3554MedJan 15, 2019
    risk 0.00cvss 5.9epss 0.01

    Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00