VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 197 of 206
  • CVE-2023-33297HigMay 22, 2023
    risk 0.00cvss 7.5epss 0.01

    Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.

  • CVE-2023-27734MedApr 4, 2023
    risk 0.00cvss 5.5epss 0.00

    An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.

  • CVE-2023-26485MedMar 31, 2023
    risk 0.00cvss 5.3epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing…

  • CVE-2023-24824MedMar 31, 2023
    risk 0.00cvss 5.3epss 0.01

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing…

  • CVE-2023-28644MedMar 30, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the…

  • CVE-2023-1654HigMar 27, 2023
    risk 0.00cvss 7.8epss 0.00

    Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.

  • CVE-2023-1605HigMar 23, 2023
    risk 0.00cvss 7.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

  • CVE-2023-27567HigMar 3, 2023
    risk 0.00cvss 7.5epss 0.01

    In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.

  • CVE-2023-25816MedFeb 25, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in…

  • CVE-2023-23616LowJan 28, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the request. This could…

  • CVE-2022-41861MedJan 17, 2023
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.

  • CVE-2023-22470LowJan 14, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is…

  • CVE-2022-47934MedDec 24, 2022
    risk 0.00cvss 6.5epss 0.01

    Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This is caused by an incomplete fix for CVE-2022-47932 and CVE-2022-47934.

  • CVE-2022-47932MedDec 24, 2022
    risk 0.00cvss 6.5epss 0.01

    Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This vulnerability is caused by an incomplete fix for CVE-2022-47933.

  • CVE-2022-41969LowDec 1, 2022
    risk 0.00cvss 2.4epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11,…

  • CVE-2022-41968LowDec 1, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5…

  • CVE-2022-39346LowNov 25, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud…

  • CVE-2022-45873MedNov 23, 2022
    risk 0.00cvss 5.5epss 0.00

    systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put…

  • CVE-2022-4006LowNov 15, 2022
    risk 0.00cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to…

  • CVE-2022-39330MedOct 27, 2022
    risk 0.00cvss 4.8epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing…