VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 20 of 206
  • CVE-2026-67864HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component

  • CVE-2026-48834HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption…

  • CVE-2026-67862HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.

  • CVE-2026-67861HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

  • CVE-2026-67856HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests

  • CVE-2026-67855HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.

  • CVE-2026-56846HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

  • CVE-2026-67978HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.

  • CVE-2026-67977HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-67973HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

  • CVE-2026-67976HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.

  • CVE-2026-18358HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel…

  • CVE-2024-25039HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to…

  • CVE-2026-9322HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

  • CVE-2026-58182HigJul 29, 2026
    risk 0.49cvss 8.6epss 0.00

    The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version…

  • CVE-2026-14981HigJul 28, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

  • CVE-2026-62518HigJul 21, 2026
    risk 0.49cvss 7.6epss 0.00

    Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60180HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2026-47057HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java…

  • CVE-2026-47018HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…