CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,148)
page 202 of 208| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4952 | Low | 0.00 | 3.5 | 0.01 | Jul 17, 2023 | A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The… | ||
| CVE-2023-36818 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2023 | Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this… | ||
| CVE-2023-3108 | Med | 0.00 | 6.2 | 0.00 | Jul 11, 2023 | A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system. | ||
| CVE-2023-3398 | Hig | 0.00 | 7.5 | 0.01 | Jun 26, 2023 | Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. | ||
| CVE-2023-34109 | Med | 0.00 | 6.5 | 0.01 | Jun 7, 2023 | zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which are using the second argument of the zxcvbn function. It can result in an unbounded resource consumption as the user inputs array… | ||
| CVE-2023-33297 | Hig | 0.00 | 7.5 | 0.01 | May 22, 2023 | Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023. | ||
| CVE-2023-27734 | Med | 0.00 | 5.5 | 0.00 | Apr 4, 2023 | An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp. | ||
| CVE-2023-26485 | Med | 0.00 | 5.3 | 0.01 | Mar 31, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing… | ||
| CVE-2023-24824 | Med | 0.00 | 5.3 | 0.01 | Mar 31, 2023 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing… | ||
| CVE-2023-28644 | Med | 0.00 | 5.7 | 0.01 | Mar 30, 2023 | Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the… | ||
| CVE-2023-1654 | Hig | 0.00 | 7.8 | 0.00 | Mar 27, 2023 | Denial of Service in GitHub repository gpac/gpac prior to 2.4.0. | ||
| CVE-2023-1605 | Hig | 0.00 | 7.5 | 0.01 | Mar 23, 2023 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6. | ||
| CVE-2023-27567 | Hig | 0.00 | 7.5 | 0.01 | Mar 3, 2023 | In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel. | ||
| CVE-2023-25816 | Med | 0.00 | 4.3 | 0.01 | Feb 25, 2023 | Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in… | ||
| CVE-2023-23616 | Low | 0.00 | 3.5 | 0.01 | Jan 28, 2023 | Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the request. This could… | ||
| CVE-2022-41861 | Med | 0.00 | 6.5 | 0.01 | Jan 17, 2023 | A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. | ||
| CVE-2023-22470 | Low | 0.00 | 3.5 | 0.01 | Jan 14, 2023 | Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is… | ||
| CVE-2022-47934 | Med | 0.00 | 6.5 | 0.01 | Dec 24, 2022 | Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This is caused by an incomplete fix for CVE-2022-47932 and CVE-2022-47934. | ||
| CVE-2022-47932 | Med | 0.00 | 6.5 | 0.01 | Dec 24, 2022 | Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This vulnerability is caused by an incomplete fix for CVE-2022-47933. | ||
| CVE-2022-41969 | Low | 0.00 | 2.4 | 0.01 | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11,… |
- risk 0.00cvss 3.5epss 0.01
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The…
- risk 0.00cvss 6.5epss 0.01
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this…
- risk 0.00cvss 6.2epss 0.00
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.
- risk 0.00cvss 7.5epss 0.01
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.
- risk 0.00cvss 6.5epss 0.01
zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which are using the second argument of the zxcvbn function. It can result in an unbounded resource consumption as the user inputs array…
- risk 0.00cvss 7.5epss 0.01
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.
- risk 0.00cvss 5.5epss 0.00
An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.
- risk 0.00cvss 5.3epss 0.01
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing…
- risk 0.00cvss 5.3epss 0.01
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing…
- risk 0.00cvss 5.7epss 0.01
Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the…
- risk 0.00cvss 7.8epss 0.00
Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.
- risk 0.00cvss 7.5epss 0.01
Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.
- risk 0.00cvss 7.5epss 0.01
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
- risk 0.00cvss 4.3epss 0.01
Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in…
- risk 0.00cvss 3.5epss 0.01
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the request. This could…
- risk 0.00cvss 6.5epss 0.01
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.
- risk 0.00cvss 3.5epss 0.01
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is…
- risk 0.00cvss 6.5epss 0.01
Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This is caused by an incomplete fix for CVE-2022-47932 and CVE-2022-47934.
- risk 0.00cvss 6.5epss 0.01
Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This vulnerability is caused by an incomplete fix for CVE-2022-47933.
- risk 0.00cvss 2.4epss 0.01
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11,…