VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 196 of 206
  • CVE-2023-52425HigFeb 4, 2024
    risk 0.00cvss 7.5epss 0.02

    libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.

  • CVE-2024-23824MedFeb 2, 2024
    risk 0.00cvss 4.7epss 0.01

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is…

  • CVE-2023-50020HigJan 2, 2024
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

  • CVE-2023-50019MedJan 2, 2024
    risk 0.00cvss 5.9epss 0.01

    An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.

  • CVE-2023-26157MedJan 2, 2024
    risk 0.00cvss 5.5epss 0.01

    Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

  • CVE-2023-41102HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version…

  • CVE-2023-42813MedNov 13, 2023
    risk 0.00cvss 6.1epss 0.01

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno…

  • CVE-2023-45150MedOct 16, 2023
    risk 0.00cvss 4.3epss 0.00

    Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It…

  • CVE-2023-5595MedOct 16, 2023
    risk 0.00cvss 5.5epss 0.00

    Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.

  • CVE-2023-3153MedOct 4, 2023
    risk 0.00cvss 5.3epss 0.01

    A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.

  • CVE-2023-43771MedSep 22, 2023
    risk 0.00cvss 5.5epss 0.00

    In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.

  • CVE-2022-48571HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.

  • CVE-2022-37050MedAug 22, 2023
    risk 0.00cvss 6.5epss 0.01

    In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the…

  • CVE-2023-34872MedJul 31, 2023
    risk 0.00cvss 5.5epss 0.01

    A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

  • CVE-2023-38498MedJul 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite…

  • CVE-2022-4952LowJul 17, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The…

  • CVE-2023-36818MedJul 14, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this…

  • CVE-2023-3108MedJul 11, 2023
    risk 0.00cvss 6.2epss 0.00

    A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.

  • CVE-2023-3398HigJun 26, 2023
    risk 0.00cvss 7.5epss 0.01

    Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.

  • CVE-2023-34109MedJun 7, 2023
    risk 0.00cvss 6.5epss 0.01

    zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which are using the second argument of the zxcvbn function. It can result in an unbounded resource consumption as the user inputs array…