VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 195 of 206
  • CVE-2023-52340HigJul 5, 2024
    risk 0.00cvss 7.5epss 0.01

    The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket.

  • CVE-2024-5216HigJun 25, 2024
    risk 0.00cvss 7.5epss 0.01

    A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to create users with…

  • CVE-2023-45196HigJun 24, 2024
    risk 0.00cvss 7.5epss 0.01

    Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this…

  • CVE-2024-3153MedJun 6, 2024
    risk 0.00cvss 6.5epss 0.01

    mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. An attacker with the ability…

  • CVE-2024-4284MedMay 19, 2024
    risk 0.00cvss 4.9epss 0.01

    A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id…

  • CVE-2023-7258MedMay 15, 2024
    risk 0.00cvss 4.8epss 0.00

    A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past…

  • CVE-2024-32663HigMay 7, 2024
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 traffic can lead to Suricata using a large amount of memory. The issue has been addressed in Suricata 7.0.5…

  • CVE-2024-31994MedApr 19, 2024
    risk 0.00cvss 6.5epss 0.00

    Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. Mealie will attempt to retrieve this file in whole. If it can be retrieved, it may be stored on the file system in whole (leading to…

  • CVE-2024-31992MedApr 19, 2024
    risk 0.00cvss 6.5epss 0.01

    Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to a remote server, however these requests are not rate-limited. While there are efforts to prevent DDoS by implementing a…

  • CVE-2024-1569HigApr 16, 2024
    risk 0.00cvss 7.5epss 0.01

    parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of…

  • CVE-2024-3569HigApr 10, 2024
    risk 0.00cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [validatedRequest] middleware…

  • CVE-2021-47208MedApr 8, 2024
    risk 0.00cvss 4.3epss 0.01

    The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

  • CVE-2024-27100MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead to excessive resource…

  • CVE-2024-27085MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version of Discourse. Users are…

  • CVE-2024-24827MedMar 15, 2024
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process. Do note that the impact…

  • CVE-2024-27088NonFeb 26, 2024
    risk 0.00cvss 0.0epss 0.01

    es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.

  • CVE-2024-23835HigFeb 26, 2024
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround,…

  • CVE-2024-24814HigFeb 13, 2024
    risk 0.00cvss 7.5epss 0.01

    mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes…

  • CVE-2024-23323MedFeb 9, 2024
    risk 0.00cvss 4.3epss 0.01

    Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1,…

  • CVE-2024-24575HigFeb 6, 2024
    risk 0.00cvss 7.5epss 0.01

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop,…