VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 21 of 191
  • CVE-2025-65890HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index.

  • CVE-2025-65889HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-65888HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or excessively large dimension value.

  • CVE-2025-65886HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes.

  • CVE-2025-55102HigJan 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more than 15 different source address can lead to denial of service. An attacker can send a malicious packet…

  • CVE-2025-66960HigJan 21, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

  • CVE-2025-66959HigJan 21, 2026
    risk 0.49cvss 7.5epss 0.05

    An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

  • CVE-2026-21945HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle…

  • CVE-2026-21637HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error),…

  • CVE-2025-59464HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.00

    A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger…

  • CVE-2025-9466HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.01

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

  • CVE-2025-9465HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.00

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

  • CVE-2025-9464HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.00

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.

  • CVE-2025-9283HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.01

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

  • CVE-2025-9282HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.01

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

  • CVE-2025-9281HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.01

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots

  • CVE-2025-9280HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.00

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.

  • CVE-2025-9279HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.01

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

  • CVE-2025-9278HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.00

    A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.

  • CVE-2026-0517HigJan 17, 2026
    risk 0.49cvss 7.5epss 0.00

    CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash