VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 199 of 206
  • CVE-2022-24741LowMar 9, 2022
    risk 0.00cvss 3.5epss 0.02

    Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud…

  • CVE-2022-0695MedFeb 24, 2022
    risk 0.00cvss 5.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0476MedFeb 23, 2022
    risk 0.00cvss 5.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-21698HigFeb 15, 2022
    risk 0.00cvss 7.5epss 0.06

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through…

  • CVE-2022-21721MedJan 28, 2022
    risk 0.00cvss 5.9epss 0.02

    Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial of service attack for anyone using i18n functionality. In order to be affected by this CVE, one must use next start or a custom…

  • CVE-2022-21653MedJan 5, 2022
    risk 0.00cvss 5.9epss 0.01

    Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not…

  • CVE-2021-3622MedDec 23, 2021
    risk 0.00cvss 4.3epss 0.05

    A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to…

  • CVE-2021-41168MedOct 21, 2021
    risk 0.00cvss 6.5epss 0.01

    Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was found to be vulnerable to denial of service attacks to its reference table implementation. References written in markdown `…

  • CVE-2021-33609MedOct 13, 2021
    risk 0.00cvss 4.3epss 0.01

    Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.

  • CVE-2021-41115MedOct 7, 2021
    risk 0.00cvss 4.3epss 0.02

    Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via arbitrary regular expressions. Malicious organization…

  • CVE-2021-41118MedOct 4, 2021
    risk 0.00cvss 5.3epss 0.01

    The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. In affected versions unsanitised input of regular expression date within the parameters of the DPL parser function, allowed for the…

  • CVE-2021-32832MedAug 30, 2021
    risk 0.00cvss 4.3epss 0.02

    Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3,…

  • CVE-2021-23425MedAug 18, 2021
    risk 0.00cvss 5.3epss 0.02

    All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.

  • CVE-2021-3679MedAug 5, 2021
    risk 0.00cvss 5.5epss 0.01

    A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources…

  • CVE-2021-32763MedJul 20, 2021
    risk 0.00cvss 4.3epss 0.01

    OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `quote` method that implements the logic behind the Quote button in the discussion forums, and it uses a regex to strip ``…

  • CVE-2021-32722MedJun 28, 2021
    risk 0.00cvss 6.5epss 0.01

    GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an uncontrolled resource consumption vulnerability. A large amount of page moves within a short space of time could overwhelm Database servers due to improper…

  • CVE-2020-14326HigJun 2, 2021
    risk 0.00cvss 7.5epss 0.01

    A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with higher CPU time spent searching and adding the entry. This flaw allows an attacker to cause a denial of service.

  • CVE-2021-23388MedJun 1, 2021
    risk 0.00cvss 5.3epss 0.02

    The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via email validation.

  • CVE-2021-32617MedMay 17, 2021
    risk 0.00cvss 4.7epss 0.01

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used…

  • CVE-2021-32816MedMay 14, 2021
    risk 0.00cvss 6.5epss 0.01

    ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Client before version 3.16.60 has a regular expression denial-of-service vulnerability. This was fixed in commit 6687fb. There is a full report available in the…