VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 25 of 191
  • CVE-2025-53645HigJul 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthenticated remote attacker can send…

  • CVE-2025-49716HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

  • CVE-2025-6714HigJul 7, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20…

  • CVE-2025-53481HigJul 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Allocation.This issue affects Mediawiki - IPInfo Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

  • CVE-2025-44531HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt.

  • CVE-2025-44528HigJun 23, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via sending a crafted LL_Pause_Enc_Req packet during the authentication and connection phase, causing a Denial of Service (DoS).

  • CVE-2025-44203HigJun 20, 2025
    risk 0.49cvss 7.5epss 0.01

    In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL…

  • CVE-2025-33068HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-32724HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

  • CVE-2025-48053HigJun 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, sending a malicious URL in a PM to a bot user can cause a reduced the availability…

  • CVE-2025-26481HigMay 15, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2025-26783HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, W1000, Modem 5300, and Modem 5400. Incorrect handling of undefined values leads to a Denial of Service.

  • CVE-2025-26677HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-30730HigApr 15, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2025-27486HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27485HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27473HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27470HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-27469HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

  • CVE-2025-26680HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.