CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,104)
page 196 of 206| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-52425 | Hig | 0.00 | 7.5 | 0.02 | Feb 4, 2024 | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. | ||
| CVE-2024-23824 | Med | 0.00 | 4.7 | 0.01 | Feb 2, 2024 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is… | ||
| CVE-2023-50020 | Hig | 0.00 | 7.5 | 0.01 | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF. | ||
| CVE-2023-50019 | Med | 0.00 | 5.9 | 0.01 | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response. | ||
| CVE-2023-26157 | Med | 0.00 | 5.5 | 0.01 | Jan 2, 2024 | Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c. | ||
| CVE-2023-41102 | Hig | 0.00 | 7.5 | 0.01 | Nov 17, 2023 | An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version… | ||
| CVE-2023-42813 | Med | 0.00 | 6.1 | 0.01 | Nov 13, 2023 | Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno… | ||
| CVE-2023-45150 | Med | 0.00 | 4.3 | 0.00 | Oct 16, 2023 | Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It… | ||
| CVE-2023-5595 | Med | 0.00 | 5.5 | 0.00 | Oct 16, 2023 | Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV. | ||
| CVE-2023-3153 | Med | 0.00 | 5.3 | 0.01 | Oct 4, 2023 | A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured. | ||
| CVE-2023-43771 | Med | 0.00 | 5.5 | 0.00 | Sep 22, 2023 | In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program. | ||
| CVE-2022-48571 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP. | ||
| CVE-2022-37050 | Med | 0.00 | 6.5 | 0.01 | Aug 22, 2023 | In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the… | ||
| CVE-2023-34872 | Med | 0.00 | 5.5 | 0.01 | Jul 31, 2023 | A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open. | ||
| CVE-2023-38498 | Med | 0.00 | 4.3 | 0.01 | Jul 28, 2023 | Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite… | ||
| CVE-2022-4952 | Low | 0.00 | 3.5 | 0.01 | Jul 17, 2023 | A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The… | ||
| CVE-2023-36818 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2023 | Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this… | ||
| CVE-2023-3108 | Med | 0.00 | 6.2 | 0.00 | Jul 11, 2023 | A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system. | ||
| CVE-2023-3398 | Hig | 0.00 | 7.5 | 0.01 | Jun 26, 2023 | Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. | ||
| CVE-2023-34109 | Med | 0.00 | 6.5 | 0.01 | Jun 7, 2023 | zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which are using the second argument of the zxcvbn function. It can result in an unbounded resource consumption as the user inputs array… |
- risk 0.00cvss 7.5epss 0.02
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
- risk 0.00cvss 4.7epss 0.01
mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is…
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
- risk 0.00cvss 5.9epss 0.01
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
- risk 0.00cvss 5.5epss 0.01
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version…
- risk 0.00cvss 6.1epss 0.01
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno…
- risk 0.00cvss 4.3epss 0.00
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It…
- risk 0.00cvss 5.5epss 0.00
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
- risk 0.00cvss 5.3epss 0.01
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.
- risk 0.00cvss 5.5epss 0.00
In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.
- risk 0.00cvss 7.5epss 0.01
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
- risk 0.00cvss 6.5epss 0.01
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the…
- risk 0.00cvss 5.5epss 0.01
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
- risk 0.00cvss 4.3epss 0.01
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite…
- risk 0.00cvss 3.5epss 0.01
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The…
- risk 0.00cvss 6.5epss 0.01
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this…
- risk 0.00cvss 6.2epss 0.00
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.
- risk 0.00cvss 7.5epss 0.01
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.
- risk 0.00cvss 6.5epss 0.01
zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which are using the second argument of the zxcvbn function. It can result in an unbounded resource consumption as the user inputs array…